Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Provider and vendor reports trace a shift. In 2024 and early 2025, Microsoft, OpenAI and Google reported threat actors using LLMs mainly as productivity tools. From mid-2025, Anthropic reported Claude Code carrying out an extortion campaign under human direction and a state-sponsored espionage campaign with people at a few decision points; Google reported malware that queries LLMs during execution, including by Russia’s APT28; and Sysdig, Google and ThreatDown reported agent-driven extortion, automated credential harvesting and a botnet built around an agent framework. Google also reported in September 2026 that it had not yet seen fully autonomous attack pipelines in the wild. These reports come from the organizations that detected the activity, mostly on their own platforms, so they show that agent-driven attacks happen, not how common they are.
The findings behind it
3 corroborated, 1 reportedEach finding carries a status that changes as new work arrives. What the statuses mean.
- Attackers have used AI agents to carry out much of the work of real intrusions, from reconnaissance to credential theft and extortion, with people directing them at a few decision points.Corroborated observed · 5 evidence records
- Malware that queries a language model during execution to generate commands has been used in live operations, including by a state-backed group; self-rewriting variants have been seen only in testing.Corroborated observed · 2 evidence records
- Google's threat intelligence team attributes to AI the development of a zero-day exploit that criminal actors prepared for mass exploitation, based on characteristics of the code.Reported reported · 1 evidence record
- Malicious or compromised agent extensions, MCP servers, and skills have been published to public registries and used against real users.Corroborated observed · 4 evidence records
Answer history
Answers are never edited after the fact. A revision adds a new answer and keeps the earlier ones here.
- 2026-09-26moderate confidencecurrentIncreasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.Correction: the extortion campaign ran under human direction, security vendors are among the sources, and Google has not yet seen fully autonomous pipelines in the wild. Government threat reports are still missing from the corpus.
- 2026-09-25moderate confidenceIncreasingly to run parts of intrusions: providers report agent-driven espionage, extortion and credential theft, and malware that queries LLMs as it runs.Revised after twelve threat-intelligence and malware reports from 2024 to September 2026 (Anthropic, ESET, Google, Microsoft with OpenAI, Sysdig and ThreatDown) were added, closing most of the coverage gap the first answer described.
- 2026-09-25low confidenceToo thinly covered here to answer well. The corpus records an exploit attributed to AI and malicious agent packages, but few provider threat reports.First answer, drawn from the findings linked here.