Back to feed

Autonomous AI Agents Harvest Thousands of Credentials in Six Hours

2 min
Autonomous AI Agents Harvest Thousands of Credentials in Six Hours

This digest was compiled by AI from multiple sources — links to the originals are below.

A financially motivated hacking group used an autonomous multi-agent AI framework to compromise thousands of credentials in under six hours, Google Threat Intelligence Group reported. The campaign began with a cloud infrastructure breach and deployed credential stealers SANDCLOCK and DUSTMAKER to harvest developer and cloud credentials. GTIG warns that agentic AI is shrinking defenders' response windows as attackers automate multistep decisions.

Key Facts

  • The autonomous campaign compromised thousands of credentials in under six hours, according to Google Threat Intelligence Group.
  • The financially motivated actor TeamPCP (Altered Spider, UNC6780) targeted PyPI, npm, and Docker Hub in large-scale supply chain compromises.
  • Credential stealers SANDCLOCK and DUSTMAKER were deployed after initial compromise, with DUSTMAKER being a cross-platform JavaScript payload optimized for CI/CD pipelines.
  • GTIG has not observed fully autonomous attack pipelines deployed against targets in the wild, but an alleged China-linked group used Gemini to design an automated penetration testing framework.

Autonomous Attack Framework

Mandiant investigators traced the campaign to a suspected financially motivated actor that first broke into an organization's cloud infrastructure. The attacker assembled an autonomous framework from an AI coding chatbot, a prompt, and a set of agent instructions, with preconfigured markdown playbooks driving scanning and harvesting. Troubleshooting and IP rotation ran without an operator, and traffic left the victim's own addresses, making it appear legitimate. GTIG said the integration of AI-assisted coding tools has accelerated software development cycles and increased targeting of developers, AI coding assistants, and LLM security scanning tools.

TeamPCP Supply Chain Operations

TeamPCP, also tracked as Altered Spider and UNC6780, conducted a series of large-scale software supply chain compromises targeting PyPI, npm, and Docker Hub. After initial compromise, the group deployed credential stealers SANDCLOCK and DUSTMAKER to obtain sensitive data and target AI coding assistants. Stolen data was monetized through direct sale or partnerships with ransomware and data theft extortion groups. SANDCLOCK, used in March and April 2026, was written in Python, operated on Linux, interacted with Kubernetes, and included container escape functionality. DUSTMAKER, used from April onward, is a cross-platform JavaScript payload optimized for CI/CD pipelines without container escape functionality, focusing on credential theft for extortion.

Adversarial AI Evolution

The report 'From Prompting to Autonomy: The Evolution of Adversarial AI' covers activity GTIG tracked over the second quarter. It follows the May edition, which documented the first confirmed case of criminals using AI to build a working zero-day exploit. GTIG said adversaries are handing multistep decisions to models, shrinking the window defenders have to react. An alleged China-linked espionage group used Gemini to design an automated penetration testing framework for port scanning, service parsing, and early intrusion work.

2 sources

Time · lag behind first