A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.

Threat actors are increasingly using agentic AI and AI-based automation to speed and scale attacks, according to a report released Tuesday by Google Threat Intelligence Group. In addition, hackers are also deliberately targeting proprietary AI models in order to steal credentials and co-opt the cloud environments of compromised organizations.

A range of state-linked and cybercriminal groups have incorporated AI into their attack frameworks in recent months, allowing them to find new targets, exploit security vulnerabilities, and explore new attack methods. Researchers warn that so many groups are incorporating AI into their toolkits that defenders should expect that AI to potentially play some role in future attacks.

“At this point, we can assume that all threat actors are using AI in some capacity, and their operations have benefited,” John Hultquist, chief analyst, GTIG, said in a statement. “Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary.”

Google researchers cited a number of campaigns where AI was incorporated into an attack life cycle:

Google researchers warn that threat actors are also engaged in model-distillation campaigns. They estimate that coordinated campaigns, some exceeding 100 million prompts, are targeting Google AI models in an attempt to extract model logic, reasoning capabilities and chain-of-thought processes.

Attackers are also deploying proxy infrastructure in an attempt to conduct large-scale automated attacks. Hackers are sending queries to get access to compromised credentials and fraudulent accounts to help them bypass standard security controls.

The researchers previously outlined efforts by threat actors to incorporate AI into their threat campaigns, including the use of frontier AI.