Google Threat Intelligence: Financially Motivated Attacker Uses AI Multi-Agent Framework to Complete Large-Scale Credential Theft in Under 6 Hours
Google Threat Intelligence Group (GTIG) documented a financially motivated attacker who used an AI coding assistant and a multi-agent framework to build and deploy a large-scale credential-stealing pipeline in under six hours with almost no human intervention. It is the first time GTIG has recorded, in actual Mandiant incident response data, an attacker using autonomous AI execution across an entire attack chain.