ZeroHour
GBHackerspublished ()ingested Mayura Kathir1

Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting

highThreat actor exploited in the wildimportance 70
AI summary · glm-5.3

Google GTIG documents a financially motivated actor using a multi-agent AI framework to automate credential harvesting, compromising over 23,800 secrets within hours.

Google Threat Intelligence Group (GTIG) documented a financially motivated actor that compromised an unnamed organization's cloud infrastructure and used a multi-agent AI framework to automate vulnerability scanning, credential harvesting, troubleshooting, and IP rotation. The operation went from planning to mass credential compromise in under six hours, harvesting more than 23,800 secrets including cloud and AI-service API keys via an exposed C2 dashboard called 'Recon'. The actor directed specialized agents using an AI coding chatbot and Markdown instruction files such as AGENTS.KNOWLEDGE.md and agentic_vuln_research.md. Google has not observed fully autonomous zero-day exploitation; the shift automates labor-intensive tasks like reconnaissance, account validation, and infrastructure management, sharply shrinking detection windows.

  • GTIG: agentic AI framework ran mass credential-harvesting operation in under six hours
  • Over 23,800 harvested secrets, including cloud tokens and AI-service API keys, managed via exposed 'Recon' C2 dashboard
  • Actor orchestrated agents via AI coding chatbot and Markdown instruction files like AGENTS.KNOWLEDGE.md
  • No fully autonomous zero-day exploitation observed; automation targets reconnaissance, validation, and infrastructure rotation
  • Defenders should enforce phishing-resistant MFA, least-privilege cloud identities, API key rotation, and secret scanning
Full article722 words · extracted from gbhackers.com · click to collapse

Threat actors are moving from using artificial intelligence as a productivity aid to deploying autonomous agentic systems that can execute major portions of an intrusion with minimal human intervention.

Google Threat Intelligence Group (GTIG) has documented a financially motivated actor that used a multi-agent framework to plan, build, and run a mass credential-harvesting operation in less than six hours after gaining access to a cloud environment.

The activity represents a consequential operational shift. Rather than relying on an operator to manually triage scan results, debug scripts, rotate infrastructure, and validate stolen accounts.

Those files served as reusable operational playbooks, allowing the framework to automate discovery and credential collection at scale.

According to GTIG’s findings, the threat actor first compromised an unnamed organization’s cloud infrastructure.

From that foothold, the agentic framework handled vulnerability scanning, credential harvesting, operational troubleshooting, and IP-address rotation.

The campaign ultimately compromised thousands of third-party credentials.

This model does not mean the AI independently identified and weaponized an unknown zero-day vulnerability. Google said it had not observed fully autonomous, real-world zero-day exploitation pipelines.

Instead, the immediate danger lies in automation of well-understood but labor-intensive attacker tasks: reconnaissance, exposed-service identification, credential extraction, account validation, infrastructure management, and post-compromise decision-making.

That distinction matters for defenders. Existing weaknesses overprivileged cloud identities, exposed secrets, unpatched internet-facing assets, reusable passwords, weak API-key governance, and insufficient detection engineering can now be exploited faster and at a much larger scale.

Agentic systems reduce the time and expertise needed to string these weaknesses into a repeatable campaign.

GTIG separately identified an exposed command-and-control server hosting an automated reconnaissance and credential-management framework known as “Recon.”

Google Threat Intelligence Group said that, the attacker used an AI coding chatbot, a prompt, and predefined Markdown instruction files to direct specialized agents through the attack workflow.

Agentic AI Exploitation

The exposed environment contained agent configuration and knowledge files, including AGENTS.KNOWLEDGE.md, and agentic_vuln_research.md, as well as agent memory directories.

By leveraging autonomous AI agents to research vulnerabilities, scan server-side infrastructure, and execute targeted exploits, the adversary automated the end-to-end post-exploitation pipeline with minimal human intervention.

Soon after discovery, the infrastructure evolved into a production-style dashboard designed to organize, validate, and manage more than 23,800 harvested secrets in real time.

Automated Reconnaissance and Credential Management Framework (Source : GTIG).
 Automated Reconnaissance and Credential Management Framework (Source : GTIG).

The data set reportedly included API keys associated with cloud and AI services, demonstrating why machine identities have become an increasingly attractive target for financially motivated actor.

Unlike conventional infostealer operations, where stolen data is commonly dumped in logs and resold, an agentic credential pipeline can continuously assess which secrets remain valid, prioritize higher-value accounts, and feed usable access directly into subsequent attack stages.

actors leveraging AI to augment various phases of the attack lifecycle, particularly for use cases such as vulnerability research, malware development, and generating information operations (IO) content.

Stolen cloud tokens and AI-service API keys can enable lateral movement, data access, resource abuse, and further attacks against connected organizations.


Threat actors are leveraging AI across all stages of the attack lifecycle  (Source : GTIG).
Threat actors are leveraging AI across all stages of the attack lifecycle (Source : GTIG).

The principal security impact is a sharply reduced detection-and-response window. An intrusion that once required days of human-driven reconnaissance and execution can now move from initial access to high-volume credential compromise within hours.

Automated troubleshooting also makes attacks more resilient: when a scan fails, an agent can adjust commands, change infrastructure, or route around errors without waiting for an operator.

Organizations should prioritize controls that limit credential exposure and slow down automated abuse.

This includes enforcing phishing-resistant multi-factor authentication, rotating and revoking exposed API keys, applying least privilege to cloud identities, monitoring impossible-travel and anomalous token use, and continuously scanning repositories, collaboration platforms, and cloud workloads for hard-coded secrets.

Security teams should also correlate high-volume reconnaissance, rapid authentication attempts, unusual IP rotation, and cloud-control-plane activity.

In the agentic era, isolated alerts may appear routine; the critical signal is the speed and orchestration linking them together.

The development reinforces a broader threat-intelligence conclusion: AI is not replacing attackers, but it is turning established intrusion tradecraft into a faster, more scalable, and increasingly persistent service.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/agentic-ai-exploitation/