Skip to content
Privacy & Security

Silicon Valley’s AI Agent Push Has Been Paying Off—for Cybercriminals

Threat actors in China, Iran, and Russia have been moving away from simple prompt-and-reply chatbots to more autonomous systems, a new report from Google has found.
By

Reading time 3 minutes

Comments (1)

AI companies have made a lot of noise about the technology supercharging healthcare, scientific discovery, education, productivity, and just about everything else worth caring about. But so far, probably the most dramatic change wrought by the AI race has been the sudden appearance of dangerous new cybersecurity threats.

The most infamous of these are the autonomous hacks launched by swarms of AI agents, the most recent of which was first reported last week (even though OpenAI, the company behind the agents, had reportedly been aware of the incident for quite a while longer). But it’d be a mistake to think that new cyber threats in the age of AI are only coming from mindless, reward-hacking bots; there are still plenty of good ol’ fashioned human hackers, for whom new AI tools have been a godsend.

A new report from Google Threat Intelligence Group (GTIG)—a research team within Google monitoring emerging cyberthreats—found that threat actors, many of them with direct ties to the United States’ geopolitical foes, have been leveling-up the sophistication of their AI usage, transitioning from basic chatbots to more agentic, autonomous systems. 

“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG wrote in its report, which was published online Tuesday morning. “While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.” In plain English: the technology that leading AI companies (including Google) have been building into their AI systems, giving them the ability to handle complex tasks without constant hand-holding, is also making hackers’ dirty work a whole lot easier.

Some of the “adversaries” that GTIC identified in its new report appear to be backed by China, Russia, and Iran. One group, which GTIC first reported earlier this year and identified only as “UNC6508,” has been targeting American academic, medical, and military research institutions in a manner “aligned with the strategic interests of the People’s Republic of China.” According to Tuesday’s report, UNC6508 has been observed using an open source AI model within its targets’ cloud environments to steal compute without leaving the kind of trail that would be left if they’d been using a commercial, publicly available AI model.

“[UNC6508] continues to research how to set up and use AI tools, including using open models locally, and researching vulnerabilities in AI models themselves,” GTIC wrote in its new report.

In another case reported by GTIC, threat actors traced to Iran used Gemini to generate realistic deepfakes to be used in social engineering campaigns. Rather than entering one prompt after another to fine-tune the deepfakes’ appearance, they deployed the AI model to autonomously define “granular technical parameters—including camera angles, studio lighting, and realistic facial textures—to achieve photorealistic visual outputs.”

GTIC also reported “coordinated campaigns” being carried out “on a regular basis” to distill its proprietary AI systems, which it said is a violation of Google’s terms of service and could be subject to legal action. Though distillation has long been a widely used practice within the AI industry to develop new models, it’s recently become a political flashpoint. Leading American developers including OpenAI and Anthropic have accused their Chinese rivals of distilling their AI systems in an effort to gain a competitive edge, and the White House has vowed to crack down on what it’s described as “deliberate, industrial-scale campaigns to distill U.S. frontier AI systems.”

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.