NewsLayer.com

Threat actors are giving AI agents a bigger role in cyberattacks

AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.

Help Net Security

Publisher

Sep 8, 2026 at 1:44 PM UTC · Updated il y a 3 jours · 3 min de lecture

Threat actors are giving AI agents a bigger role in cyberattacks
Image via Help Net Security

Key Signal

23,800+ Harvested secrets managed

Last Updated

il y a 3 jours

AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.

(Source: Google)

The report draws on Mandiant incident response engagements, threat actor tracking, and live platform defenses. Researchers observed attackers moving from basic prompts toward workflows where AI systems handle several connected tasks.

A six-hour credential theft campaign

In Q2 2026, Mandiant investigated a suspected financially motivated threat actor that compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework.

The attacker used an AI coding chatbot, a prompt, and agent instructions to plan, build, and execute a mass credential-harvesting campaign in less than six hours. Thousands of third-party credentials were compromised.

“The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention,” GTIG researchers wrote.

The attacker operated from the victim’s cloud infrastructure, which allowed attack traffic to pass through legitimate IP addresses.