Science Desk.- The multinational Google has warned of a significant shift in the malicious use of artificial intelligence (AI) by cybercriminals, noting that cybercriminals and espionage groups are already using increasingly autonomous and faster systems, capable on their own of planning, automating, and executing an attack.
The technology company released a report this Tuesday, prepared by the company’s Threat Intelligence Group, which reveals how cybercriminal attackers are massively using artificial intelligence to optimize their operations and how cybercriminals are managing to steal valuable intellectual property related to AI.
Read more: Cybercriminals are already stealing and storing data to decrypt it in the future
The “AI Threat Tracker” report prepared by a group of experts from the American company has been published a month after the company OpenAI announced the halting of its new model (Astra) after concluding that it reached a “critical” level in cybersecurity, as it was capable of identifying and developing vulnerabilities and planning cyberattacks autonomously.
Google analysts have concluded that advanced AI ‘agent’ use cases are no longer experimental and are no longer limited solely to vulnerability detection, and they have noted the multiple incidents that have targeted AI-based models and systems in the technology, healthcare, and media and entertainment sectors in North America and Europe.
AI, a force multiplier for attacks
To satisfy their growing demand for AI access, cybercriminals are also stealing credentials and purchasing capabilities on the ‘darknet,’ the report notes, pointing out that some criminal groups, mainly from Russia, China, Iran, and North Korea, are using these technologies to automate credential theft, create malicious code, and conduct industrial espionage.
Analysts have highlighted the “worrying” trend of compromising the software supply chain, where criminals manipulate programming assistants and open-source repositories, and in addition to exploiting external tools, they are stealing AI intellectual property and hijacking cloud resources to run their own models.
The research concludes that artificial intelligence has become a force multiplier that allows for the execution of complex attacks in a matter of a few hours.
The paper cites numerous examples, including how the cyber-espionage group Basin Castle—linked to China—is using language models as support in various tasks, from target research to troubleshooting in the middle of an intrusion, or how another Chinese group attempted to use Gemini (the AI model developed by Google) to build an automated penetration testing framework that would execute the initial phases of intrusions.
Analysts also detected a massive credential theft campaign that was orchestrated by a ‘multi-agent architecture’ deployed on stolen infrastructure, and verified how that campaign managed to scale and autonomously compromise thousands of credentials in just six hours.
Another group of cybercriminals (TeamPCP) has focused, for example, on the AI supply chain, deploying malware specifically designed to exploit emerging artificial intelligence systems, and managed to infect and damage some of those tools and even trick their assistants into recommending malicious sites to developers.
And another group of computer experts (DPRK) linked to North Korea were detected stealing legitimate user accounts to connect their systems massively and automatically to artificial intelligence systems, thereby multiplying the speed and reach of their attacks.
Attacks that can overwhelm response and defense capacity
“At this point, we can assume that all threat actors are using AI in one way or another and that their operations have benefited from it,” noted John Hultquist, Chief Analyst at Google’s Threat Intelligence Group (GTIG).
The multinational’s expert has corroborated their concern regarding the vulnerabilities, but has stressed that it is not just a problem for the technology sector and that AI is being applied in many other areas.
“The challenge will be especially complex as it executes autonomously, creating a faster and larger-scale adversary; cybercriminals, like those who carried out a massive campaign in just six hours, will lean toward attacks that execute at a speed faster than we can respond,” Hultquist described.




