Particle.news

Attackers Run AI Agents on Stolen Cloud Hosts to Speed Credential Theft

Google's new report shows criminals and state‑linked groups install open‑source models on hacked third‑party servers to hide activity that scales attacks.

Overview

  • Google’s Threat Intelligence Group reported Tuesday that multiple criminal and intelligence‑linked groups have moved from simple LLM prompts to multi‑agent, agentic frameworks that automate reconnaissance, exploitation, and post‑exploit tasks.
  • Researchers found attackers running open‑source AI models on compromised third‑party cloud environments so their queries avoid commercial model monitoring and guardrails, which helps them evade detection and tracing.
  • A financially motivated group tracked as UNC6780 used Dustmaker malware to steal CI/CD tokens and publish compromised packages to PyPI, npm, and Docker Hub, which let it poison developer workflows and sell access to stolen AI credentials.
  • GTIG discovered an exposed Recon command‑and‑control panel that managed roughly 23,800 harvested secrets, including cloud and AI API keys, and described incidents where an attacker built and launched a mass credential‑harvesting campaign in under six hours.
  • The report says fully autonomous zero‑day discovery and exploitation is not yet widespread, but defenders have detected and disrupted some campaigns and now urge short‑lived scoped credentials, stronger server‑side authorization, continuous testing, and tighter vetting of internal AI use.