Multi-Agent AI Framework Harvested Thousands of Credentials in Under Six Hours

Google's Threat Intelligence Group documented a financially motivated cyberattack in which an autonomous multi-agent AI framework was used to steal thousands of credentials from cloud infrastructure. The attacker first gained access to a target organization's cloud environment, then deployed the system from within it, allowing malicious requests to appear as legitimate traffic. Built using an AI coding chatbot and Markdown-based operational playbooks, the framework autonomously handled vulnerability scanning, credential collection, IP rotation, and self-correction without human intervention at each step. Mandiant's incident-response analysis confirmed the entire operation, from initial setup to mass credential compromise, was completed in under six hours. The case highlights how the same self-correcting, resilient design patterns used in legitimate AI agent tooling can be repurposed to run offensive campaigns with minimal human oversight.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in