The Google Threat Intelligence Group (GTIG) says threat actors are moving beyond simple prompt-based interactions with large language models and using multi-agent frameworks across several stages of attacks. These systems can coordinate tasks, troubleshoot failures and adapt their actions with little human intervention.
In one financially motivated incident, an attacker compromised an organization’s cloud infrastructure and, in less than six hours, planned, built and deployed a mass credential-harvesting campaign using an AI coding chatbot, a prompt and markdown agent instructions. The agents managed vulnerability scanning, harvested thousands of third-party credentials, troubleshot problems in real time, rotated IP addresses and routed traffic through legitimate, compromised cloud environments.
GTIG also observed China-linked cyberespionage actors testing AI-powered development tools for automated exploitation and post-exploitation. The Russia-based UNC5792 used AI models to automate monitoring bots that searched Telegram channels for information of interest to the government.
GTIG said fully autonomous hacking is not yet widespread and reported no fully autonomous pipelines for zero-day discovery and network exploitation against real-world targets. Google said Gemini detected many abuses early and helped the company disrupt campaigns and ban associated accounts.
The report also mentions Gemini AI distillation operations involving 100 million prompts. The Blue Report 2026 measures defenses across 338 million simulations in customer production environments.
Comments
0No comments yet. Be the first to comment.