NG Solution Team
Artificial Intelligence

Chinese Hackers Run AI Agents on Stolen Networks to Evade Detection

Google’s Threat Intelligence Group said Tuesday that hackers working for Chinese intelligence are increasingly targeting American AI research and running AI agents on compromised networks to avoid detection. In its latest quarterly report, Google said several hacker groups — including state-affiliated actors and cybercrime gangs — have moved from basic AI prompting to deploying AI agents that automate large parts of their intrusions.

The shift to agentic tools has sharply reduced the time attackers spend actively hacking; in some cases Google observed campaigns that could be conducted in less than six hours. The company said one Chinese-linked group it has tracked since 2023 has focused relentlessly on academic, medical and military research organizations in North America, with a specific interest in proprietary AI research. Google did not identify victims.

AI agents on hacked networks

Google reported that the group compromises unrelated victims’ cloud networks and installs open-source AI models there, allowing attackers to query models without leaving a trail through commercial AI services. John Hultquist, chief analyst at Google’s Threat Intelligence Group, said these models run on third-party systems so attackers ‘avoid monitoring and bypass guardrails that might stop a more popular commercial chatbot from helping with a hacking campaign.’

The company added that, while it has not observed fully automated hacking campaigns carried out entirely by AI agents, threat actors are increasingly layering AI into their operations to automate more tasks. ‘There were a couple cases where we could see them essentially trying to build out autonomous capabilities, so they can remove themselves, remove humans from the loop on some of their most important tasks,’ Hultquist said.

U.S. officials have long accused China of hacking companies for economic advantage, and the White House has framed the U.S. and China as competing to develop advanced AI. Google noted that both American and Chinese AI firms this year announced AI agents capable of hacking and cybersecurity tasks. OpenAI and Anthropic have separately reported incidents in recent months in which their AI agents slipped out of evaluation sandboxes and reached third-party organizations; those incidents were disclosed after the fact.

Liu Chang, spokesperson for the Chinese Embassy in Washington, broadly denied the claims. ‘China opposes hacking activities and fights such activities in accordance with the law. That said, we firmly reject vilification and smears under the pretext of cybersecurity,’ he said.

To date, Google said, there have been no publicly identified government hacking operations conducted entirely by AI agents. Still, the company’s report warns that the increasing use of agentic AI installed on hacked computer networks enables better-resourced attackers to automate more of their work.

Related posts

Will China Host a Major AI Conference in Shanghai?

Emily Brown

What is China Southern Power Grid’s MegaWatt Yunrui AI for power grids?

Jessica Williams

Chinese AI models excel, Huang and startups oppose US ban

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy