Agentic AI Attacks: The Evolution From Prompting to Autonomy

Artificial intelligence in attacks has ceased to be a mere accelerant for routine and has begun assuming entire segments of an operation. On September 8, the Google Threat Intelligence Group described the shift from isolated prompts toward agentic systems that chain together several stages of an attack and sharply diminish human involvement. One such pipeline was assembled and launched in under six hours, as detailed in the group’s analysis of the evolution of adversarial AI.
A Cloud Breach Turned Credential Harvest
After compromising a cloud resource, the attacker deployed a multi-agent system to hunt for vulnerable services and gather credentials en masse. The AI itself governed the scanning, corrected its own errors, and rotated IP addresses. Ultimately, the campaign compromised thousands of third-party credentials, and the Recon panel GTIG discovered processed more than 23,800 stolen secrets, including API keys for cloud and AI services.
Poisoning the Software Supply Chain
Another vector concerns software development. The group UNC6780 concealed malicious instructions within project configurations and JavaScript comments. Through prompt injections, they thereby coerced AI assistants into running commands or threw LLM scanners off their analysis. In April, ReversingLabs uncovered a similar peril, reporting that Claude Opus became the co-author of a commit that introduced a malicious dependency into a crypto project.
AI Systems as Targets Themselves
AI systems have simultaneously become a target in their own right. Mandiant investigated thefts of models, source code, prompts, and research from companies across several industries. Google also records attempts to transplant the capabilities of closed models into foreign systems through distillation. Notably, some such campaigns exceeded 100 million requests and passed through thousands of compromised or counterfeit accounts.
The Rise of LLMjacking
LLMjacking is likewise growing, whereby foreign cloud resources are harnessed for costly AI computation. In April, an attacker infiltrated a cloud through an exposed GitHub token, enabled Gemini Enterprise, created a service account with Editor rights, and requested additional quotas on NVIDIA RTX 6000. On underground marketplaces, meanwhile, the average price of AI-service accounts more than doubled in 2026.
Human Hands Still on the Wheel
For all this automation, GTIG has yet to observe fully autonomous attacks against real targets. Attackers now convert published vulnerability disclosures into working n-day exploits more swiftly and bind models to offensive tooling. Nevertheless, humans still set the direction and control the pivotal stages. Google responds by blocking associated accounts and reinforcing Gemini’s protective safeguards.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.