Logo
FrontierNews.ai

AI Agents Are Now Targets for Hackers: Here's How Attackers Are Weaponizing Them

AI agents have become a new frontier for cybercriminals, who are now weaponizing autonomous systems to orchestrate sophisticated attacks, compromise software supply chains, and develop exploits faster than defenders can respond. According to Google Cloud's Mandiant AI Risk and Resilience Report 2026, the shift from human-guided AI assistants to autonomous, agentic systems has created unprecedented security challenges that traditional defenses are struggling to address.

Over the past year, enterprises accelerated their adoption of agentic AI, deploying distributed autonomous systems empowered to execute application programming interface (API) calls, optimize production configurations, and analyze complex telemetry across hybrid cloud environments. But as organizations embraced this technology, threat actors evolved their tactics in parallel. Adversaries moved from basic AI chat prompting for research and troubleshooting to autonomous or agentic attack orchestration, offloading operational tasks to AI for scaled, multi-stage, sophisticated attacks.

How Are Threat Actors Using AI Agents to Attack Organizations?

Mandiant's threat intelligence team observed a variety of threat actors deploying or incorporating agentic tools like Hexstrike and Strix for autonomous reconnaissance, validation of vulnerabilities, and credential harvesting. What makes these attacks particularly dangerous is that the language learning model (LLM), an AI system trained on vast amounts of text data, functions as a participant in the attack rather than merely an advisor, enabling pivoting and decision-making at machine speed.

The sophistication of these attacks is evident in several documented cases. In one incident, Mandiant investigated a breach where a threat actor compromised a software-as-a-service (SaaS) provider and hijacked an active AI coding assistant session on a developer's workstation. The AI assistant, operating as a trusted interpreter within the environment, recommended the installation of an external software package that had been poisoned by the attacker. Once the recommendation was accepted, the attacker used the developer's active session to install an infostealer using a poisoned PyPI package, harvest GitHub OAuth tokens, and deploy the self-propagating Shai-Hulud worm across approximately 100 internal code repositories.

In another case, Mandiant identified anomalous activity originating from a compromised long-lived developer continuous integration and continuous deployment (CI/CD) credential at a global healthcare organization. The threat actor utilized this credential to initialize an unisolated virtual machine instance and transform it into a live, AI-assisted offensive hub. Instead of developing malware offline, the attacker integrated LLMs directly into the live server environment to debug and optimize offensive tools in real-time through an iterative workflow.

What Supply Chain Vulnerabilities Are Emerging in AI Ecosystems?

Supply chain attacks targeting AI components represent a critical emerging threat. In February 2026, VirusTotal researchers observed the weaponization of OpenClaw AI agent skills by attackers who distributed backdoors, droppers, infostealers, and remote access tools disguised as legitimate, helpful automation packages. This demonstrates how threat actors are leveraging traditional supply chain tactics such as embedding malware in libraries and adapting it to skills used by agentic AI to gain access to AI systems.

The following month, Mandiant responded to numerous incidents related to supply chain compromises associated with the threat actor UNC6780, also known as TeamPCP. In addition to stealing credentials for AI services and proprietary AI data, UNC6780 implemented more than half a dozen different methods to exploit AI tools and the open source software ecosystem, including manipulating the behavior of AI coding assistants and LLM security scanners through prompt injection, a technique where attackers insert malicious instructions into AI inputs to change the system's behavior.

How Are AI Models Being Used to Develop Zero-Day Exploits?

Perhaps most alarming, threat actors are now using AI models to discover and weaponize previously unknown vulnerabilities. In May 2026, Google's Threat Intelligence Group disclosed the first publicly confirmed case of a cybercriminal using an AI-developed zero-day exploit to plan a mass exploitation campaign. The threat actor leveraged an AI model to support the discovery and weaponization of a vulnerability implemented using a Python script that enables users to bypass two-factor authentication (2FA) on a popular open-source, web-based system administration tool.

This represents a fundamental shift in the threat landscape. For the sixth consecutive year, the exploitation of vulnerabilities remains the leading initial infection vector. However, AI is now transforming vulnerability management as frontier models can autonomously discover zero-day vulnerabilities and chain complex exploits at machine speed. Consequently, securing modern environments requires moving beyond manual triage to deploy an always-on, machine-speed defense.

How to Defend Against AI-Powered Attacks

  • Secure AI-Assisted Development: Enforce integrated development environment (IDE) and command-line interface (CLI) verification hooks to validate all AI-recommended third-party software dependencies against cryptographic checksums and approved allowlists. Isolate local credentials to prevent extensions from accessing raw API keys, long-lived OAuth tokens, or secrets, and restrict workstation network egress to route all dependency traffic through secure, internal repositories.
  • Implement Adaptive Identity Controls: Traditional security boundaries blur when a single poisoned data source, model dependency, or extension hook can transform a trusted agent into an unauthorized conduit for internal reconnaissance, lateral movement, or autonomous breakout from a sandbox. Organizations must transition to clearly identified, adaptive identity controls that can respond to evolving threats in real-time.
  • Accelerate Defensive Velocity: Defending against autonomous threats requires accelerating defensive velocity and reorienting security operations centers (SOCs) toward real-time behavioral telemetry rather than reactive incident response. This means deploying machine-speed detection and response capabilities that can match the speed of AI-driven attacks.
  • Build Signal Logic for API Aggregators: Threat actors are establishing an emerging ecosystem of custom middleware, proxy relays, and automated registration pipelines to bypass safety guardrails and billing constraints in their use of premium accounts on commercial AI platforms. Language model providers can build signal logic to analyze network infrastructure associated with these types of API aggregators to detect and block malicious activity.

Why Is AI Agent Detection Becoming Critical?

As AI agents proliferate across enterprises, the ability to detect and distinguish between legitimate automation and malicious agent activity has become essential. According to research from HUMAN Security, AI agent detection is an emerging discipline in cybersecurity, web infrastructure, and enterprise risk that focuses on distinguishing human users, benign automation, and autonomous agents that plan and execute tasks in real browsers and APIs.

HUMAN's research team analyzed a broad range of AI agents and found that all of them rely on one or more of three major automation frameworks: Selenium, Playwright, and Puppeteer, most commonly Playwright. While some agents use LLMs to more efficiently translate user prompts into automation scripts, they ultimately run those tasks through the same automation engines that have been known and detectable by antibot systems for years.

However, effective detection depends on evaluating how traffic behaves, not just where it appears to come from. Modern AI agents often reuse familiar automation techniques while varying how they present themselves across sessions. Some execute from stable infrastructure, while others inherit consumer device characteristics, rotate identifiers, or operate within full browser environments designed to closely resemble real users.

Key detection signals include network context, browser authenticity, execution environment, interaction behavior, and session evolution. By correlating these signals across multiple data sources, defenders can distinguish between human users, benign automation, and autonomous agents, even as AI agent implementations evolve.

The convergence of autonomous AI systems and sophisticated threat actors represents a watershed moment for enterprise security. Organizations that fail to adapt their defenses to this new reality face the prospect of attacks orchestrated at machine speed, exploits developed by AI, and supply chains compromised through poisoned AI-recommended packages. The time to act is now.