Autonomous AI Agents Harvest Thousands of Credentials in Under Six Hours
Cybercriminals are increasingly using autonomous artificial intelligence to accelerate attacks, and a new campaign observed by Google Threat Intelligence Group (GTIG) demonstrates just how quickly these operations can scale.

In one case, a financially motivated threat actor compromised cloud infrastructure and used an AI coding assistant together with predefined instructions and a multi-agent framework to automate a large-scale credential-harvesting operation. According to Google, the attackers compromised thousands of third-party credentials in less than six hours.
The AI-driven system was capable of managing vulnerability scanning, troubleshooting failures and changing source IP addresses with limited human involvement. Instead of manually executing each stage of an attack, operators provided the objective and operational instructions while autonomous agents handled much of the execution.
The incident represents a significant change in the economics and speed of cyberattacks: AI is increasingly being used not just to write malicious code, but to coordinate entire attack workflows.
Key Takeaways
- A financially motivated threat actor used an autonomous, multi-agent AI framework to conduct credential theft at scale.
- Thousands of third-party credentials were compromised in under six hours.
- Attackers supplied an AI coding chatbot with a prompt and predefined operational instructions.
- AI agents automated vulnerability scanning, credential harvesting and troubleshooting.
- The system also handled IP rotation without continuous human intervention.
- Google is seeing increasing attacks against proprietary AI models, AI development environments and cloud infrastructure.
- Threat actors are targeting developer tools, CI/CD pipelines and software supply chains.
- Malware such as SANDCLOCK and DUSTMAKER has been used to steal developer, cloud and AI-related credentials.
- Open-weight AI models are becoming attractive to attackers because they can be operated locally without the visibility available through commercial AI providers.
- AI-assisted attacks are reducing the time defenders have to detect and respond to malicious activity.
The Six-Hour Credential Harvesting Operation
The most striking case highlighted by Google involved an unnamed organization whose cloud infrastructure was first compromised by attackers.
Once inside the environment, the threat actor deployed an autonomous multi-agent system designed to conduct credential harvesting.
The attackers provided three major components:
AI coding assistant + Prompt + Preconfigured agent instructions
The instructions effectively served as an operational playbook, allowing the AI agents to determine and execute the next steps required to continue the campaign.
Rather than requiring an operator to manually investigate each target, run individual scans and troubleshoot failed operations, the autonomous system handled these tasks dynamically.
The result was a campaign capable of compromising thousands of third-party credentials in less than six hours.
From Human-Driven Attacks to Agentic Operations
Traditional cyberattacks often require an operator to manually progress through multiple stages:
Reconnaissance → Scanning → Exploitation → Credential Theft → Troubleshooting → Persistence → Exfiltration
An autonomous attack framework changes this model.
The attacker can instead provide a high-level objective and allow software agents to execute repetitive or adaptive tasks.
In the campaign observed by GTIG, the AI system could:
- Manage vulnerability scanning
- Identify potential targets
- Harvest credentials
- Troubleshoot unsuccessful operations
- Adapt to changing conditions
- Rotate IP addresses
- Continue the operation with limited human intervention
This creates a much faster attack cycle and allows a relatively small number of operators to manage activity that would traditionally require considerably more manual effort.
TeamPCP and the Growing AI Supply-Chain Threat
The activity forms part of a broader campaign ecosystem associated with TeamPCP, also tracked as Altered Spider and UNC6780.
The financially motivated actor has been linked to compromises involving major software distribution ecosystems, including:
- PyPI
- npm
- Docker Hub
These platforms are particularly attractive because malicious packages can potentially reach large numbers of developers and automated build environments.
Following an initial compromise, attackers have deployed credential-stealing malware designed to collect sensitive information from development and cloud environments.
The strategy is especially dangerous because developer credentials can provide access to source repositories, package registries, CI/CD environments, cloud accounts and AI development platforms.
DUSTMAKER Targets AI Development Environments
One malware family highlighted by Google is DUSTMAKER, which emerged as a successor to the earlier SANDCLOCK credential stealer.
DUSTMAKER is a cross-platform JavaScript payload designed with CI/CD environments in mind.
Unlike SANDCLOCK, DUSTMAKER does not rely on container escape capabilities as part of its core functionality. Instead, its primary focus is credential theft that can ultimately support extortion operations.
The malware also introduces techniques specifically designed to target AI coding environments.
Attackers can poison AI assistant workspaces with malicious instructions and use prompt injection to influence AI-powered security tools.
This creates a new layer in the software supply-chain threat:
Compromised Package → Developer Environment → Credential Theft → AI Assistant Manipulation → Further Compromise
SANDCLOCK: Earlier Generation of the Campaign
SANDCLOCK was observed earlier in 2026 and is associated with activity sometimes referred to publicly as CanisterWorm.
According to GTIG, SANDCLOCK is primarily Python-based and targets Linux and Kubernetes environments.
Its capabilities include:
- Cloud credential theft
- Developer credential theft
- Cryptocurrency wallet targeting
- Kubernetes-related activity
- Container escape functionality
The evolution from SANDCLOCK to DUSTMAKER demonstrates how threat actors are adapting their malware to environments increasingly dominated by automated development and AI-assisted workflows.
AI Infrastructure Is Becoming a High-Value Target
The threat is no longer limited to stealing passwords and API keys.
Google reported that threat actors are increasingly targeting organizations' proprietary AI assets, including:
- AI models
- Training data
- Source code
- Prompts
- AI skills and configurations
- Research
- API credentials
- Cloud infrastructure
These assets can be stolen for espionage, sold to other criminals or used as leverage during extortion operations.
In some cases, attackers have also compromised cloud environments and used them to operate their own AI workloads.
This effectively turns the victim's infrastructure into an unauthorized computing platform.
Attackers Deploy Local AI Models Inside Compromised Clouds
GTIG also identified activity involving UNC6508, a China-linked threat actor suspected of compromising cloud environments and deploying a local large language model.
Instead of sending activity through a commercial AI provider, the attackers used an open-weight model running directly within the compromised environment.
This approach can provide attackers with an important advantage: reduced external visibility.
Commercial AI services can potentially monitor suspicious activity through API usage and provider-side telemetry. A locally deployed model removes much of that centralized visibility.
Attackers can therefore operate AI systems within compromised infrastructure while using their own tools, prompts and workflows.
Open-Weight Models Create a Difficult Security Balance
Open-weight AI models offer legitimate benefits to businesses and researchers, including greater control, customization and the ability to operate models locally.
However, the same characteristics can create security challenges.
An attacker running a model locally does not necessarily have to interact with a provider that can detect or restrict suspicious behavior.
GTIG warned that increasingly capable open models—including modified or uncensored variants—could lower the barrier for malicious actors seeking AI-assisted capabilities.
This creates a difficult balance for the security industry:
More accessible AI enables innovation—but it can also make advanced capabilities easier for attackers to deploy privately.
AI-Assisted Reconnaissance and Exploit Development
Google's observations extend beyond credential theft.
Threat actors are also experimenting with AI agents for reconnaissance, exploit development and operational decision-making.
One China-linked espionage group reportedly used Google's Gemini to develop an automated penetration-testing framework.
The planned architecture was designed to:
- Observe the target environment.
- Assess the available information.
- Determine an appropriate next action.
- Execute that action.
- Continue adapting to the environment.
The framework included planned capabilities such as port scanning and service identification.
This is an important development because it moves AI from being a simple coding assistant toward acting as an autonomous operator capable of making decisions during an intrusion.
Multiple Threat Groups Are Already Using AI
GTIG reported AI-assisted activity across a broad range of threat actors.
Examples include:
China-linked groups
Threat actors have used AI models such as Gemini, Claude and Codex for:
- Exploit development
- Target research
- Spear-phishing content
- Troubleshooting intrusion operations
- Intelligence gathering
The group known as Basin Castle, also tracked as Mustang Panda, has reportedly used LLMs during operational tasks.
Another China-linked actor, Ravine Castle, also known as APT24, has used Gemini for intelligence collection, attack development and influence operations.
Russia-linked activity
The Russia-linked Sandworm group has used Gemini to support intelligence gathering, social engineering and workflow automation during operations targeting Ukraine.
Another Russian-linked cluster, UNC5792, has reportedly used AI to process information from Telegram channels.
Iran-linked activity
The threat actor Calanque Ion, also tracked as APT42, has used generative AI for reconnaissance and targeted social-engineering activity.
North Korean activity
North Korean-linked clusters have also incorporated AI into their operations.
Google reported AI-related activity involving UNC5267 and UNC5342, including the use of hijacked identities to register large numbers of LLM API accounts.
Another financially motivated North Korean actor, Midnight Neptune, has used commercial and open-weight AI models for social engineering, supply-chain manipulation and automated backdoor development.
Stolen AI Credentials Become a Criminal Commodity
The growth of AI development has created another valuable category of credentials.
Infostealer malware such as Lumma Stealer, Vidar and ACR Stealer can target developer environments and AI-related configuration files.
These may contain:
- API keys
- Cloud credentials
- Developer tokens
- Authentication cookies
- AI service credentials
- Repository access tokens
- Package registry credentials
Once stolen, these credentials can be sold underground or used directly by attackers.
A compromised AI API account can also allow criminals to access expensive computing resources, automate malicious operations or conduct activity while charging the associated costs to the legitimate account owner.
Why AI-Powered Attacks Are So Dangerous
The most important change is not necessarily that AI can write malware.
Cybercriminals have already automated many parts of their operations.
The bigger concern is speed and adaptability.
An autonomous agent can repeatedly perform a task, evaluate the result and attempt another approach without waiting for an operator.
That means attackers can potentially compress operations that previously took days into hours—or even less.
The six-hour credential campaign demonstrates this shift clearly.
For defenders, the problem becomes a race between:
Automated Attack Execution vs. Human-Led Security Response
If detection, investigation and containment remain heavily dependent on manual processes, security teams may struggle to keep pace.
Security Recommendations for Organizations
Organizations adopting AI coding assistants and autonomous agents should treat these systems as part of the enterprise attack surface.
1. Protect AI and Developer Credentials
Use short-lived credentials wherever possible and avoid storing long-lived API keys inside developer workstations, repositories or AI configuration files.
2. Enforce Least Privilege
AI agents should receive only the permissions required for their specific task.
Avoid giving autonomous agents unrestricted access to:
- Production environments
- Source repositories
- Secrets
- Cloud administration
- Identity systems
3. Monitor AI Agent Activity
Security teams should monitor:
- Unexpected AI API usage
- New model deployments
- Unusual cloud compute consumption
- New service accounts
- Unexpected GPU instances
- Suspicious agent tool calls
- Large-scale credential access
4. Secure CI/CD Pipelines
Protect build environments against malicious packages and unauthorized modifications.
Monitor changes to:
- Package dependencies
- Build scripts
- Container images
- Deployment configurations
- CI/CD secrets
5. Rotate Compromised Credentials Quickly
When a developer environment or cloud workload is compromised, assume associated credentials may have been exposed.
Revoke and rotate affected tokens rather than simply changing passwords.
6. Monitor Cloud Resources
Unexpected AI workloads running inside cloud environments should be treated as potential indicators of compromise.
Security teams should investigate:
- Unexpected compute instances
- GPU resource consumption
- New containers
- Unknown model downloads
- Unusual outbound connections
- Unexpected API consumption
7. Log Agent Decisions and Tool Usage
Where possible, maintain audit logs covering:
- Agent prompts
- Tool calls
- Files accessed
- Commands executed
- Credentials requested
- External connections
- Code modifications
These records can be critical during an investigation.
8. Establish Human Approval Gates
High-risk agent actions should require human approval, particularly when an agent attempts to:
- Access secrets
- Modify production code
- Create cloud resources
- Change permissions
- Deploy software
- Communicate externally
- Transfer sensitive data
What Security Teams Should Watch For
SOC teams should consider adding AI-specific behavioral detections to existing monitoring programs.
Potential indicators include:
- Sudden spikes in AI API consumption
- Unusual authentication from developer environments
- Rapid credential access across multiple systems
- Large numbers of failed authentication attempts followed by successful access
- Unexpected IP address rotation
- New cloud workloads running AI models
- Unauthorized changes to AI assistant workspaces
- Suspicious package installations
- Unexpected modifications to CI/CD pipelines
- AI agents accessing resources outside their normal scope
A key detection principle is behavioral correlation.
A single AI API request may not be suspicious. A combination of new credentials, unusual cloud compute, package changes, rapid scanning and large-scale authentication activity should receive significantly higher priority.
The Bigger Picture
Google's findings indicate that AI is becoming embedded across multiple stages of the cyberattack lifecycle.
The progression increasingly looks like:
Reconnaissance → Vulnerability Discovery → Exploit Development → Credential Theft → Lateral Movement → Data Theft → Extortion
AI can assist with individual steps, but autonomous agent frameworks have the potential to connect those steps into a continuous workflow.
That is the real security challenge.
Organizations are no longer defending only against attackers who use AI as a productivity tool. They increasingly need to prepare for software-driven adversaries capable of operating with limited human intervention.
Bottom Line
The six-hour credential-harvesting campaign is a strong indication that agentic AI is changing the speed and scale of cybercrime.
Threat actors are using AI coding assistants, autonomous agents, malware and compromised cloud environments to automate tasks that traditionally required significant human effort.
At the same time, AI systems themselves are becoming high-value targets. Developer credentials, model files, prompts, source code and AI infrastructure can all provide valuable access to attackers.
For defenders, simply blocking malicious AI prompts or banning AI tools is unlikely to be sufficient.
The priority should be strong identity controls, least-privilege access, secure CI/CD pipelines, cloud monitoring, credential protection and strict governance around autonomous agents.
The central lesson is simple: if an AI agent can act autonomously, it must be secured like a privileged enterprise identity—not treated merely as a productivity application.
Threat Classification
| Category | Details |
|---|---|
| Threat Type | AI-enabled cybercrime / Credential Theft |
| Primary Target | Cloud, developer and AI environments |
| Attack Automation | Autonomous multi-agent framework |
| Credential Impact | Thousands of third-party credentials |
| Reported Attack Duration | Less than six hours |
| Key Actor | Financially motivated threat actors |
| Notable Group | TeamPCP / Altered Spider / UNC6780 |
| Malware | DUSTMAKER, SANDCLOCK |
| Key Risks | Credential theft, cloud compromise, supply-chain attacks, AI abuse |
| Threat Level | Critical |
Related reporting
Attackers Use Passkey-Themed Phishing to Hijack Microsoft Cloud Accounts and Steal Data
Threat actors are using passkey-themed social engineering to compromise Microsoft 365 accounts and gain access to sensitive cloud data, according to Microsoft Threat Intelligence.
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says it identified and disrupted seven industrial-scale attempts to extract capabilities from its Claude AI models, attributing the activity to China-based AI laboratories.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Cybercriminals and state-sponsored threat actors are increasingly using artificial intelligence to automate portions of real-world cyberattacks, with Anthropic revealing that its Claude models were incorporated into multi-stage operations involving reconnaissance, exploitation, credential theft and data exfiltration.


