[Photo: Shutterstock]

[DigitalToday reporter Chi-gyu Hwang (황치규)] Cyber attackers used a multi-agent AI framework to steal thousands of credentials in under 6 hours, a case has emerged.

SiliconAngle reported on Sept. 8 (local time) that Google Mandiant Threat Intelligence Group said in a report covering its second-quarter tracking that a suspected financially motivated attacker breached an organisation's cloud infrastructure, then built an autonomous attack system and automated scanning and information gathering.

Mandiant investigators found the attacker combined an AI coding chatbot, prompts and agent prompts, then carried out follow-on scanning and collection using a preset markdown playbook. Troubleshooting and IP rotation took place without operator intervention. Outbound traffic also originated from the victim's address, making it appear like normal activity.

Google Threat Intelligence Group presented what it said was the first confirmed case of criminals creating an AI-powered zero-day exploit in a May report. This report focused on how much human involvement decreased during subsequent attack processes. But the report said it has not yet confirmed a case in which a fully autonomous attack pipeline was deployed against an actual target.

The report said a suspected China-linked espionage group designed an automated penetration testing framework that uses Gemini to carry out initial intrusion tasks on its own, including port scanning and service parsing. Google disabled assets linked to the attempt.

Keyword

#Google #Mandiant #Gemini #SiliconAngle #Mandiant Threat Intelligence Group
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.