Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Google Finds Attacker Built a Mass Credential-Theft Operation With AI Agents in Under Six Hours

What Happened

Google’s Threat Intelligence Group published findings showing threat actors moving from simple AI-assisted coding toward autonomous multi-agent frameworks capable of running entire attacks with limited oversight. In one incident, a financially motivated attacker compromised an organization’s cloud infrastructure, then used an AI coding chatbot paired with a prompt and markdown agent instructions to plan, build, and deploy a mass credential-harvesting campaign in under six hours. The AI agents managed the vulnerability-scanning pipeline, harvested thousands of third-party credentials, rotated IP addresses, and routed traffic through legitimate compromised cloud environments to evade detection, all with minimal human intervention. In a separate case, researchers found an exposed command-and-control panel named Recon managing more than 23,800 harvested secrets, including API keys, in real time. GTIG also observed China-linked and Russia-based groups experimenting with AI-assisted exploitation pipelines and Telegram-monitoring automation, though the report stops short of confirming fully autonomous zero-day discovery against live targets. Full findings are available from BleepingComputer.

Why This Matters for Canadian Organizations

The shift toward autonomous, multi-agent attack tooling compresses the window Canadian security teams have to detect and contain an intrusion, since a campaign once requiring days of manual operator work now runs in a single work shift with no human approving each step. Organizations across finance, retail, and government sectors relying on third-party credentials, API integrations, and cloud service accounts face a growing volume of automated credential-harvesting attempts rather than the smaller, hand-operated campaigns security teams have tuned their detection around. This trend arrives alongside Canada’s push under Bill C-26 to strengthen incident-reporting and cyber-resilience obligations for federally regulated critical infrastructure, and defenders relying on playbooks built around human-paced attacker behaviour face a mismatch against operations adapting in real time.

What to Do

Security teams should treat exposed API keys, cloud credentials, and third-party integration tokens as high-priority findings rather than routine hygiene issues, given AI-driven frameworks now harvest and operationalize thousands of secrets within hours of discovery. Rotate credentials on a defined schedule rather than only after a known incident, and apply short-lived, scoped tokens in place of long-lived static API keys wherever supported. Monitor for anomalous IP rotation patterns and traffic routed through legitimate cloud providers, since attackers increasingly hide inside infrastructure defenders already trust. Security operations teams should review detection rules built around slower, manual attacker behaviour and test whether current alerting catches compressed, automated attack timelines measured in hours rather than days. Ongoing coverage is available from BleepingComputer.

Enjoy this article? Don’t forget to share.