Agentic AI Accelerates Cyberattacks, Threatening Defenders' Response Times
Google's Threat Intelligence Group has identified a growing trend among cyber threat actors to use agentic artificial intelligence systems in their attacks. These AI systems can coordinate multiple stages of an attack with limited human involvement, accelerating activity and compressing the response window for defenders.
In a recent report, GTIG highlighted several examples of this trend, including one incident where an attacker used an AI system to plan, build, and run a multi-agent credential-harvesting campaign in less than six hours. The framework collected thousands of credentials and handled tasks such as vulnerability scanning, credential collection, troubleshooting, and IP rotation.
GTIG also noted that state-linked groups are broadening their use of AI, using large language models for activities ranging from target research to troubleshooting during intrusions. Another actor attempted to develop an automated penetration-testing framework, while UNC6780 (also known as TeamPCP) sought to compromise developers through malicious packages and model-context-protocol servers.
The report warned that threat actors are increasingly seeking proprietary models, code, prompts, research data, credentials, and cloud computing capacity, widening the security problem beyond the misuse of public chatbots. GTIG recommends that organizations monitor agent and cloud identities, look for unusual high-speed task sequences, restrict access to model and development assets, and preserve human review over sensitive actions.