Google warned this Tuesday of a significant shift in the malicious use of Artificial Intelligence, with cybercriminals and espionage groups turning to increasingly autonomous systems capable of planning, automating and executing attacks in a short time. The "AI Threat Tracker" report concluded that the use of advanced AI agents is no longer experimental and no longer limited to vulnerability detection, with several incidents identified against AI-based models and systems in the technology, healthcare, media and entertainment sectors in Europe and North America.
According to analysts, criminal groups primarily from Russia, China, Iran and North Korea are using these technologies to automate credential theft, create malicious code and conduct industrial espionage operations. Google also warned of a "concerning" trend of software supply chain attacks, through the manipulation of programming assistants and open-source code repositories, considering that AI has become a "force multiplier" that enables complex operations to be carried out in just a few hours.
Among the cases identified is the "Basin Castle" cyberespionage group, linked to China, which uses language models at various stages of operations, from target research to error resolution during an intrusion. Experts also detected an attempt by a Chinese group to use Gemini, an AI model developed by Google, in building an automated testing framework designed to execute the initial phases of an intrusion.
In another campaign, AI was implemented on stolen infrastructure and used to orchestrate a massive credential theft attack that managed to expand and autonomously compromise thousands of credentials in just six hours. Google highlighted that the vulnerabilities associated with the malicious use of AI are not an exclusive problem of the technology sector, since these tools are being applied across an increasingly wide range of areas.



