Hackers build AI frameworks for widescale credential theft
Summary
Threat actors are increasingly using multi-agent AI frameworks (systems where multiple AI agents work together autonomously to accomplish complex tasks) to automate credential theft and other cyberattacks, requiring less human oversight than traditional methods. In one incident, attackers deployed an autonomous framework that harvested thousands of credentials in under six hours, while another exposed command-and-control server (a central server attackers use to coordinate compromised systems) called "Recon" managed over 23,800 stolen secrets like API keys. Google's threat intelligence team found that while fully autonomous hacking hasn't become widespread yet, various state-backed and financially motivated groups are experimenting with AI to automate reconnaissance, credential theft, malware development, and exploitation.
Solution / Mitigation
Google reported that Gemini, its AI model, caught many of these abuses early and responded in accordance with its safety protocols, allowing Google to take additional action, disrupt the campaigns, and ban the associated accounts. However, no specific technical mitigation, patch, or version update is explicitly described in the source for defending against or remediating this threat.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
First tracked: September 8, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%