A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.
Permission granted by David Jones
Threat actors are increasingly using agentic AI and AI-based automation to speed and scale attacks,according to a report released Tuesdayby Google Threat Intelligence Group. In addition, hackers are also deliberately targeting proprietary AI models in order to steal credentials and co-opt the cloud environments of compromised organizations.
A range of state-linked and cybercriminal groups have incorporated AI into their attack frameworks in recent months, allowing them to find new targets, exploit security vulnerabilities, and explore new attack methods. Researchers warn that so many groups are incorporating AI into their toolkits that defenders should expect that AI to potentially play some role in future attacks.
“At this point, we can assume that all threat actors are using AI in some capacity, and their operations have benefited,” John Hultquist, chief analyst, GTIG, said in a statement. “Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary.”
AI innovation
Google researchers cited a number of campaigns where AI was incorporated into an attack life cycle:
- A China-nexus espionage group with a history of targeting government entities recently built an AI-assisted automated exploitation and post-exploitation pipeline using AI-based development tools. The actor employed a tool called CC Switch to operate various large language models that queried Claude, Gemini or Codex. These tools helped create custom exploit scripts and spear-phishing lures.
- A China-nexus group tracked as Basin Castle queried LLMs to profile high-value targets, develop local social engineering lures and write custom malware.
- An Iran-nexus group tracked as Calanque Ion has leveraged generative AI – including Google’s Gemini – for reconnaissance and social engineering. They used AI specifically to target email addresses, create localized social engineering lures and translate content across local languages. The group also used AI to try to reverse-engineer software.
Probing AI models
Google researchers warn that threat actors are also engaged in model-distillation campaigns. They estimate that coordinated campaigns, some exceeding 100 million prompts, are targeting Google AI models in an attempt to extract model logic, reasoning capabilities and chain-of-thought processes.
Attackers are also deploying proxy infrastructure in an attempt to conduct large-scale automated attacks. Hackers are sending queries to get access to compromised credentials and fraudulent accounts to help them bypass standard security controls.
The researcherspreviously outlined efforts by threat actors to incorporate AI into their threat campaigns, including the use of frontier AI.
Filed Under:Cyberattacks,Threats
