
Google says China-linked hackers are now running artificial intelligence models inside stolen networks to hide while they steal.
Story Snapshot
- Google’s Threat Intelligence Group reports hackers use on-target AI to mask intrusions
- Targets include North American academic, medical, and military research organizations
- Attackers move from simple prompts to autonomous agents that speed up operations
- Trend extends a long China-linked playbook of stealth and living off the land
China-Linked Operators Shift To On-Target AI
Google’s Threat Intelligence Group reported that China-linked hackers now deploy artificial intelligence on the very networks they compromise. That placement lets the models blend traffic with normal business activity and avoid obvious outbound signs.
The report says groups have shifted from basic prompting to AI agents that plan, troubleshoot, and automate parts of an intrusion lifecycle. This change cuts human delays, increases precision, and reduces the noisy errors that trigger alarms in security tools.
Google described attackers routing tasks through compromised cloud accounts and trusted services to look legitimate. Some agents manage scanning, credential theft, and privilege steps in sequence, with built-in error handling.
That means fewer failed logins, fewer odd spikes, and fewer red flags. This approach mirrors a known pattern in Chinese cyber operations: stay quiet, live off the land, and move within common tools instead of dropping loud malware families.
Chinese hackers are running AI on stolen networks to avoid detection, Google says
One China-linked group targets academic, medical and military AI research, the report sayshttps://t.co/ZRMtKlIwML— Emily Turrettini (@textually) September 8, 2026
High-Value Targets: Research And Intellectual Property
One group tracked since 2023 targeted academic, medical, and military research organizations in North America, and sought proprietary artificial intelligence research. Google said the campaign ran for more than a year before exposure, underscoring long dwell times prized in espionage work.
The aim appears clear: collect sensitive research data and the know-how that powers next-generation models and biotech. This is not smash-and-grab cybercrime; it is patient collection aligned with strategic priorities.
A report earlier tied Google actions to disruptions of a separate China-linked cluster that hit dozens of organizations across many nations.
While each group has its own tools and targets, the theme holds: use valid accounts, abused cloud resources, and now embedded artificial intelligence to move quietly. That mix makes detection harder for defenders who expect obvious malware or simple command-and-control beacons.
From Prompting To Agents That Work The Problem
The report highlights a step change in how artificial intelligence is used. Early on, hackers asked chatbots to draft phishing emails or translate lures. Now, agents orchestrate whole pipelines that search for weaknesses, harvest credentials, and adapt when things break.
One public summary described agents that rotate internet addresses, route attacks through compromised cloud environments, and troubleshoot in real time to keep the campaign smooth. That cuts costs and scales operations without needing more operators.
Google and other teams have also warned that artificial intelligence can help find rare bugs and speed up exploit development. Reports this year flagged the first cases where attackers used artificial intelligence to assist in building a zero-day exploit, the kind with no patch available at discovery.
While details differ by case, the big idea is the same: artificial intelligence shortens the gap between “idea” and “working attack,” favoring the side that moves first.
Why This Fits A Well-Documented Playbook
Security firms have long described Chinese espionage groups as favoring stealth, valid credentials, and supply chain paths over loud malware drops. Mandiant’s work has chronicled years of living off the land, cloud abuse, and careful persistence by these operators.
Running artificial intelligence inside victim networks extends that same playbook. It turns the target’s own pipes, processors, and identity systems into camouflage.
Policy debates aside, the tactical lesson is simple. If your detection plan assumes artificial intelligence sits outside your walls, you are late. Logging, identity controls, and model monitoring must treat on-premises and cloud-hosted artificial intelligence like any other workload.
Limit service account sprawl. Lock down where models can run. Watch for odd resource pulls and model-to-tool chatter. Assume the attacker will try to look like your helpdesk, your data team, or your automated pipeline—because that is where the cover lives.
Practical Defenses That Raise The Cost
Defenders can raise costs with a few concrete steps. Enforce strong, phishing-resistant multifactor authentication on every admin and service account. Segment artificial intelligence workloads, with explicit allow-lists for tools, data stores, and outbound paths.
Alert on model processes that start from nonstandard hosts or unusual user contexts. Turn on detailed cloud and identity logs and ship them to a separate tenant. Hunt for slow-and-low patterns: small but steady data pulls, odd weekend compute spikes, and ticket chatter that does not match real users.
Leadership should test incident response against scenarios where artificial intelligence runs from inside the network. Tabletop: how to quarantine workloads without halting the business. Practice disabling suspect service accounts fast. Share indicators tied to agent behavior, not just malware hashes, with sector peers.
Sources:
nbcnews.com, reuters.com, gigazine.net, blog.google, bleepingcomputer.com, euronews.com













