Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation
Google GTIG reports threat actors using agentic AI to automate reconnaissance, exploit selection, and credential harvesting, compromising thousands of secrets.
Google Threat Intelligence Group's Q3 2026 AI Threat Tracker documents threat actors operationalizing agentic AI: in one Mandiant investigation, a financially motivated actor built and executed a credential-harvesting operation in under six hours, with an exposed 'Recon' framework managing more than 23,800 harvested secrets including cloud and AI-service API keys. A Chinese-speaking actor tracked as knaithe used a DeepSeek-powered Hermes Agent for automated reconnaissance and vulnerability enumeration, pivoting from Langflow to n8n and enabling manual exploitation of exposed Citrix NetScaler, Marimo, Apache Tomcat, and VPN infrastructure. Operators harvested Citrix session cookies from process memory to bypass MFA, obtained AWS credentials from compromised Marimo instances, and deployed the Go-based NKAbuse backdoor, with reported RCE and data exfiltration. Google notes fully autonomous end-to-end AI attack pipelines have not yet been observed in the wild.
- Mandiant saw agentic credential harvesting run in under six hours
- Exposed 'Recon' C2 framework managed 23,800+ harvested secrets
- knaithe's DeepSeek-powered Hermes Agent automated recon and targeting
- Session cookie theft bypassed MFA; NKAbuse backdoor on Marimo
- Defenders should hunt rapid scan-fetch-exploit behavioral patterns
Full article828 words · extracted from gbhackers.com · click to collapse
Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance, vulnerability research, exploit development and credential theft with far less hands-on-keyboard activity.
However, current evidence points to semi-autonomous, human-supervised attack chains rather than fully independent AI-driven intrusions in the wild.
Agentic AI represents a material shift from conventional generative-AI abuse.
Rather than simply asking a chatbot to write a phishing email or a PowerShell snippet, attackers can connect an LLM to scanners, asset-search engines, code repositories, web-proxy services, exploit frameworks and shell execution tools.
The resulting agent can receive an objective, formulate a plan, call tools, assess results, revise its approach and continue through multiple stages of an intrusion.
Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker documents this migration from isolated prompting toward connected workflows.
In one Mandiant investigation during the second quarter, a suspected financially motivated actor compromised cloud infrastructure and used an AI coding chatbot, agent instructions and automated tooling to build and execute a mass credential-harvesting operation in under six hours.
The reconnaissance phase is particularly vulnerable to automation.
A well-equipped agent can collect open-source intelligence, map domains and cloud assets, parse exposed services, fingerprint technologies, correlate software versions with public CVE disclosures, and prioritize targets based on exploitability.
This permits attackers to perform at machine speed the preparatory work that traditionally consumed hours or days of analyst time.
Researchers also uncovered an exposed command-and-control environment hosting an automated reconnaissance and credential-management framework named “Recon.”
The infrastructure contained agent instructions, knowledge files and persistent memory directories, and it was used to organize, validate and manage more than 23,800 harvested secrets, including cloud and AI-service API keys.
Bespoke Vulnerability Scanning and Credential Harvesting Campaign Mandiant observed a suspected financially motivated threat actor compromise an organization’s cloud infrastructure to deploy an autonomous, multi-agent attack framework.
Google characterized the evolution as a move away from passive endpoint-focused infostealers toward offensive agentic credential harvesting.

The concern is not merely faster scanning. AI agents can transform newly disclosed vulnerabilities into actionable targeting workflows by ingesting advisories, locating proof-of-concept code, checking environmental prerequisites and modifying exploit scripts when an initial attempt fails.
Google Threat Intelligence Researchers said that, the activity reportedly compromised thousands of third-party credentials, while the agent managed vulnerability scanning, troubleshooting and IP-rotation logic without continuous manual intervention.
Agentic AI Automates Cyberattacks
In a separate reported campaign attributed to a Chinese-speaking actor tracked as knaithe, a DeepSeek-powered Hermes Agent automated target reconnaissance and vulnerability enumeration.
GTIG observed a PRC-nexus cyber espionage group with a history of targeting government entities experimenting with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline.

Using a custom “1DayNews” pipeline to aggregate remote-code-execution disclosures, score exploitability and distribute targeting alerts.
Deepwatch said the agent was observed attempting a multi-stage sequence against Langflow before pivoting after configuration mismatches.
It then researched alternative targets using FOFA, selected n8n, and acquired exploit code for a chained attack path.
Although authentication barriers disrupted fully autonomous exploitation, the intelligence generated by the system enabled the operator to rapidly switch to manual exploitation of exposed Citrix NetScaler, Marimo, Apache Tomcat and IKE VPN infrastructure.
The campaign resulted in reported remote code execution, persistent reverse shells and data exfiltration.
Post-exploitation is emerging as the next high-risk stage. Once initial access is obtained, agents can accelerate credential discovery, cloud-token collection, internal asset enumeration, lateral-movement planning and payload staging.
In the knaithe activity, operators reportedly harvested Citrix session cookies from process memory to bypass MFA through session hijacking, while compromised Marimo instances yielded AWS credentials and received a Go-based NKAbuse backdoor.

For defenders, the decisive indicator is increasingly behavioral velocity rather than a single malicious hash or IP address.
Security teams should prioritize continuous external attack-surface management, rapid patching of internet-facing systems, phishing-resistant MFA, and strict access controls for development platforms such as n8n, Langflow and notebook environments.
Public administrative interfaces should be moved behind zero-trust access controls where possible.
Detection engineering must also identify rapid “scan-fetch-exploit” sequences: repeated multi-endpoint probing, immediate downloads from public exploit repositories, unexpected local web-server creation, and AI-agent or terminal processes spawning shells and network tools.
Automated containment is essential because human-only review cycles cannot reliably match an attacker that can scan, adapt and retry at machine speed.
Google cautions that it has not yet observed fully autonomous end-to-end attack pipelines deployed against targets in the wild.
Yet the documented progression is clear: adversaries are using agentic systems to reduce operational friction across the kill chain, making exposure management, identity hardening and machine-speed detection urgent defensive priorities.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/agentic-ai-automates-cyberattacks/