Google: Chinese hackers use stolen networks to run AI agents for stealthy intrusions
Google’s Threat Intelligence Group reports that state-sponsored Chinese hackers are increasingly leveraging AI agents to automate cyber intrusions against American research institutions. By installing open-source AI models on compromised third-party cloud networks, these actors bypass the monitoring and safety guardrails inherent in commercial AI services. This tactic allows them to conduct…
Key points
- Chinese hackers install open-source AI models on stolen networks to bypass commercial AI monitoring and guardrails.
- AI agents enable these groups to execute complex intrusion campaigns in less than six hours, drastically reducing active hacking time.
- Targets include North American academic, medical, and military organizations, with a specific focus on proprietary AI research.
The report highlights a specific group tracked since 2023 that targets academic, medical, and military organizations in North America, with a focus on stealing proprietary AI research. Although no fully autonomous government hacking campaigns have been identified yet, analysts note a clear trend toward removing human operators from critical tasks. The Chinese Embassy denied the allegations, characterizing them as unfounded smears, while the White House continues to frame the U.S.-China dynamic as a race for AI supremacy.
This development marks a significant shift in cyber warfare, where the integration of agentic AI into espionage operations reduces the time and labor required for complex attacks. It also raises concerns about the dual-use nature of open-source models, which can be repurposed for malicious ends when deployed outside regulated environments.
Chinese hackers are running AI on stolen networks to avoid detection, Google says
bing.com · 8 September 2026
Hackers working for Chinese intelligence are increasingly targeting American AI research and using AI in their operations, Google said Tuesday. In its latest quarterly report, Google’s Threat Intelligence Group said that several hacker groups, including both intelligence agencies and cybercrime gangs, have moved from basic AI prompting to using AI agents that automate wide swaths of their intrusion. The switch means hackers spend drastically less time actively hacking, and in some cases can conduct an entire campaign in less than six hours, the report says. Google said that one Chinese group in particular, which it has tracked since 2023, has relentlessly focused on academic, medical and military research organizations in North America and has specifically gone after proprietary AI research. Google did not name any of the victims. While American intelligence agencies also have powerful cyberespionage capabilities, the U.S. has long accused China of hacking its companies for economic advantage, a tactic Western countries generally say is unacceptable. Liu Chang, spokesperson for the Chinese Embassy in Washington, broadly denied the claims.
“China opposes hacking activities and fights such activities in accordance with the law. That said, we firmly reject vilification and smears under the pretext of cybersecurity,” he said. Google said it had observed the hacker group compromising unrelated victims’ cloud networks and installing open-source AI models — a way to query models without leaving a trail via commercial AI products. John Hultquist, the chief analyst at Google’s Threat Intelligence Group, said that running those models on a hacked third-party system allows hackers to avoid monitoring and bypass guardrails that might stop a more popular commercial chatbot from helping with a hacking campaign. “They compromise a third party and they put models on that third party. They do that instead of using, say, a commercial option where their activities are observed,” Hultquist told NBC News. The White House has repeatedly cast the U.S. and China as being in a race to develop the most cutting-edge AI. Both American and Chinese AI companies have announced this year that they have developed AI agents that are adept at hacking and cybersecurity operations. In the last several months, both OpenAI and Anthropic have reported that their own AI agents have slipped out of evaluation sandboxes to reach third-party organizations — incidents that were disclosed after the fact. Google says it has not seen threat actors wage fully automated hacking campaigns but that instead, hacking groups are continuing to layer on more AI into their operations. To date, there have been no publicly identified government hacking operations conducted entirely by AI agents. But China’s increasing reliance on agentic AI that it has installed on hacked computer networks means the country’s hackers — like any with sufficient resources and who aren’t legally constrained from such activity — can automate more of their work, Hultquist said. “There were a couple cases where we could see them essentially trying to build out autonomous capabilities, so they can remove themselves, remove humans from the loop on some of their most important tasks,” Hultquist said.
This text was published by bing.com and written by Kevin Collier. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
Coverage and discussion
8 sources- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
- Chinese hackers are running AI on stolen networks to avoid detection, Google says Press · bing.com ·
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Society & Work
All →- Anthropic reveals Houthis used Claude for ballistic missile development · 71 src
- Paul Ford: AI coding tools expose limits of autonomous software development · 1 src
- Meta adjusts AI prompt suggestions after privacy backlash over invasive questions · 5 src
- AI Chatbots Generate 1980s-Style Portraits for Instagram and X · 25 src
- Job seekers face pressure to feign AI enthusiasm in interviews · 1 src
Comments
via GitHub Discussions