Hackers working for Chinese intelligence are increasingly targeting American AI research and using AI in their operations, Google said Tuesday.
In its latest quarterly report, Google’s Threat Intelligence Group said that several hacker groups, including both intelligence agencies and cybercrime gangs, have moved from basic AI prompting to using AI agents that automate wide swaths of their intrusion.
The switch means hackers spend drastically less time actively hacking, and in some cases can conduct an entire campaign in less than six hours, the report says.
Google said that one Chinese group in particular, which it has tracked since 2023, has relentlessly focused on academic, medical and military research organizations in North America and has specifically gone after proprietary AI research. Google did not name any of the victims.
While American intelligence agencies also have powerful cyberespionage capabilities, the U.S. has long accused China of hacking its companies for economic advantage, a tactic Western countries generally say is unacceptable.
Liu Chang, spokesperson for the Chinese Embassy in Washington, broadly denied the claims.
“China opposes hacking activities and fights such activities in accordance with the law. That said, we firmly reject vilification and smears under the pretext of cybersecurity,” he said.
Google said it had observed the hacker group compromising unrelated victims’ cloud networks and installing open-source AI models — a way to query models without leaving a trail via commercial AI products.
John Hultquist, the chief analyst at Google’s Threat Intelligence Group, said that running those models on a hacked third-party system allows hackers to avoid monitoring and bypass guardrails that might stop a more popular commercial chatbot from helping with a hacking campaign.
“They compromise a third party and they put models on that third party. They do that instead of using, say, a commercial option where their activities are observed,” Hultquist told NBC News.
The White House has repeatedly cast the U.S. and China as being in a race to develop the most cutting-edge AI. Both American and Chinese AI companies have announced this year that they have developed AI agents that are adept at hacking and cybersecurity operations.
In the last several months, both OpenAI and Anthropic have reported that their own AI agents have slipped out of evaluation sandboxes to reach third-party organizations — incidents that were disclosed after the fact. Google says it has not seen threat actors wage fully automated hacking campaigns but that instead, hacking groups are continuing to layer on more AI into their operations.
To date, there have been no publicly identified government hacking operations conducted entirely by AI agents. But China’s increasing reliance on agentic AI that it has installed on hacked computer networks means the country’s hackers — like any with sufficient resources and who aren’t legally constrained from such activity — can automate more of their work, Hultquist said.
“There were a couple cases where we could see them essentially trying to build out autonomous capabilities, so they can remove themselves, remove humans from the loop on some of their most important tasks,” Hultquist said.