Summary: Google Threat Intelligence Group observed an attacker who, after gaining access to a cloud environment, used an AI coding chatbot and agent instructions to build a mass credential-theft campaign in less than six hours. Google says thousands of third-party credentials were compromised. The important change is not simply more AI use, but a much shorter path from initial access to scaled operations.
The actor investigated by Mandiant used preconfigured Markdown instructions as operational playbooks. The framework automated tasks including scanning, service parsing and credential harvesting. Google describes it as a multi-agent system able to handle operational errors and coordinate several steps of the workflow.
From assistance to workflow automation
This is a clear progression from Google's May report. At that point, GTIG had already documented AI-assisted vulnerability research, exploit development and early autonomous execution. The September report now describes a case where an attacker, after obtaining cloud access, compressed the planning, construction and execution of a larger campaign into a much shorter window.
The distinction matters: Google does not claim that an AI independently selected a victim and compromised it without a human operator. The attacker supplied access, objectives, prompts and agent instructions. What became highly automated were the technical steps that followed and the ability to scale them.
Developer tooling is becoming part of the attack surface
GTIG is also tracking UNC6780, a financially motivated actor linked to compromises across PyPI, npm, Docker Hub and GitHub-based software supply chains. Google says the group attempted to mislead AI coding assistants and LLM-based security scanners inside compromised open-source projects. In one investigated incident, a malicious GitHub Actions workflow was also created inside a proprietary AI repository.
Pandorex Analysis
For enterprises, the critical variable is therefore response time. When reconnaissance, script generation, error handling and credential collection are combined inside an agentic workflow, defenders may have far less time after the first cloud or CI/CD foothold. Long-lived API keys, broadly scoped GitHub tokens and secrets automatically exposed to build pipelines become especially dangerous.
The advantage is not one-sided. Mandiant is also using agentic source-code review to identify exploit paths faster during defensive assessments. The broader pattern is an acceleration race: both attackers and defenders are automating the same bottlenecks in analysis, code understanding and repetitive operations. Google's six-hour case shows that this shift has already moved from theory into real incident response.