Key questions/how-are-attackers-using-ai-agents

How are attackers using AI agents in real operations?

moderate confidenceRevised Sep 26, 2026Reviewed assistant-drafted
Current answer

Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.

Provider and vendor reports trace a shift. In 2024 and early 2025, Microsoft, OpenAI and Google reported threat actors using LLMs mainly as productivity tools. From mid-2025, Anthropic reported Claude Code carrying out an extortion campaign under human direction and a state-sponsored espionage campaign with people at a few decision points; Google reported malware that queries LLMs during execution, including by Russia’s APT28; and Sysdig, Google and ThreatDown reported agent-driven extortion, automated credential harvesting and a botnet built around an agent framework. Google also reported in September 2026 that it had not yet seen fully autonomous attack pipelines in the wild. These reports come from the organizations that detected the activity, mostly on their own platforms, so they show that agent-driven attacks happen, not how common they are.

The findings behind it

3 corroborated, 1 reported

Each finding carries a status that changes as new work arrives. What the statuses mean.

Answer history

Answers are never edited after the fact. A revision adds a new answer and keeps the earlier ones here.

  1. 2026-09-26moderate confidencecurrentIncreasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.Correction: the extortion campaign ran under human direction, security vendors are among the sources, and Google has not yet seen fully autonomous pipelines in the wild. Government threat reports are still missing from the corpus.
  2. 2026-09-25moderate confidenceIncreasingly to run parts of intrusions: providers report agent-driven espionage, extortion and credential theft, and malware that queries LLMs as it runs.Revised after twelve threat-intelligence and malware reports from 2024 to September 2026 (Anthropic, ESET, Google, Microsoft with OpenAI, Sysdig and ThreatDown) were added, closing most of the coverage gap the first answer described.
  3. 2026-09-25low confidenceToo thinly covered here to answer well. The corpus records an exploit attributed to AI and malicious agent packages, but few provider threat reports.First answer, drawn from the findings linked here.