{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/",
 "asOf": "2026-09-26",
 "id": "how-are-attackers-using-ai-agents",
 "order": 7,
 "question": "How are attackers using AI agents in real operations?",
 "topics": [
  "ai-enabled-intrusion",
  "ai-malware",
  "threat-intelligence"
 ],
 "answers": [
  {
   "on": "2026-09-25",
   "short": "Too thinly covered here to answer well. The corpus records an exploit attributed to AI and malicious agent packages, but few provider threat reports.",
   "body": "Google’s threat intelligence team attributes a zero-day exploit prepared for mass exploitation to AI development, and malicious agent packages and MCP servers have been used against real users. Provider and government threat-intelligence reports on attackers’ use of AI are largely not yet records in this corpus, so this answer reflects a known coverage gap more than the state of the field.",
   "confidence": "low",
   "findings": [
    "ai-developed-exploit-in-the-wild",
    "malicious-agent-packages-in-the-wild"
   ],
   "methods": [
    "ai-assisted-exploitation",
    "malicious-agent-extensions"
   ],
   "why": "First answer, drawn from the findings linked here."
  },
  {
   "on": "2026-09-25",
   "short": "Increasingly to run parts of intrusions: providers report agent-driven espionage, extortion and credential theft, and malware that queries LLMs as it runs.",
   "body": "Provider and vendor reports trace a shift. In 2024 and early 2025, Microsoft, OpenAI and Google reported threat actors using LLMs mainly as productivity tools. From mid-2025, Anthropic reported Claude Code carrying out an extortion campaign and a state-sponsored espionage campaign with people at a few decision points; Google reported malware that queries LLMs during execution, including by Russia’s APT28; and Sysdig, Google and ThreatDown reported agent-driven extortion, automated credential harvesting and a botnet built around an agent framework. These reports come from the organizations that detected the activity, mostly on their own platforms, so they show that agent-driven attacks happen, not how common they are.",
   "confidence": "moderate",
   "findings": [
    "attackers-run-intrusions-through-agents",
    "malware-queries-llms-in-operations",
    "ai-developed-exploit-in-the-wild",
    "malicious-agent-packages-in-the-wild"
   ],
   "methods": [
    "agent-orchestrated-intrusion",
    "runtime-llm-malware",
    "ai-assisted-exploitation"
   ],
   "why": "Revised after twelve threat-intelligence and malware reports from 2024 to September 2026 (Anthropic, ESET, Google, Microsoft with OpenAI, Sysdig and ThreatDown) were added, closing most of the coverage gap the first answer described."
  },
  {
   "on": "2026-09-26",
   "short": "Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.",
   "body": "Provider and vendor reports trace a shift. In 2024 and early 2025, Microsoft, OpenAI and Google reported threat actors using LLMs mainly as productivity tools. From mid-2025, Anthropic reported Claude Code carrying out an extortion campaign under human direction and a state-sponsored espionage campaign with people at a few decision points; Google reported malware that queries LLMs during execution, including by Russia’s APT28; and Sysdig, Google and ThreatDown reported agent-driven extortion, automated credential harvesting and a botnet built around an agent framework. Google also reported in September 2026 that it had not yet seen fully autonomous attack pipelines in the wild. These reports come from the organizations that detected the activity, mostly on their own platforms, so they show that agent-driven attacks happen, not how common they are.",
   "confidence": "moderate",
   "findings": [
    "attackers-run-intrusions-through-agents",
    "malware-queries-llms-in-operations",
    "ai-developed-exploit-in-the-wild",
    "malicious-agent-packages-in-the-wild"
   ],
   "methods": [
    "agent-orchestrated-intrusion",
    "runtime-llm-malware",
    "ai-assisted-exploitation"
   ],
   "why": "Correction: the extortion campaign ran under human direction, security vendors are among the sources, and Google has not yet seen fully autonomous pipelines in the wild. Government threat reports are still missing from the corpus."
  }
 ],
 "reviewedOn": "2026-09-26",
 "wouldChange": "Independent data on how often intrusions are agent-driven, from incident responders or law enforcement rather than the platforms that detected them, or cases showing that operations described as agentic were scripted by people.",
 "review": "assistant-drafted"
}