Threat Actors Target AI Models and API Credentials to Power Automated Attacks
Share
Cyber espionage groups and criminal gangs are targeting proprietary artificial intelligence (AI) assets—including model weights, source code, and API credentials—to fuel advanced cyberattacks and unauthorised AI workloads.
The Google Threat Intelligence Group (GTIG) reported that adversaries are increasingly co-opting victim cloud environments to sustain unauthorized operations, a practice known as “LLMJacking.” This shift highlights that enterprise AI assets, from model weights to cloud compute quotas, have become high-value targets for espionage, extortion, and resource theft.
Model Distillation and LLMJacking
Beyond direct data theft, attackers are increasingly employing “model distillation” attacks. In these campaigns, adversaries use massive volumes of targeted prompts to extract the knowledge, logic, and reasoning capabilities of large language models (LLMs) to train their own competing models.
Google observed campaigns involving more than 100 million prompts targeting audio, video, and image generation capabilities. These attacks are typically launched through proxy networks using thousands of compromised account credentials.
The rise in industrial-scale distillation has drawn warnings from United States authorities. The National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA) recently issued an advisory accusing China-based AI labs of engaging in such campaigns against US frontier AI models.
In addition to distillation, “LLMJacking” involves the compromise of enterprise cloud environments to hijack high-performance compute resources, allowing threat actors to run their own intensive AI operations at the victim’s expense.
Autonomous AI Agents Accelerate Exploitation
Threat actors are also leveraging “agentic AI”—AI systems capable of acting with a high degree of autonomy—to automate offensive operations. Mandiant researchers observed a financially motivated actor using compromised cloud credentials to deploy an autonomous multi-agent attack framework.
This framework enabled the attacker to plan, build, and execute a mass credential harvesting campaign in less than six hours. By using preconfigured instruction sets as operational playbooks, the AI agents autonomously managed vulnerability scanning, performed real-time troubleshooting, and executed IP rotation logic without human intervention.
In another instance, researchers identified an automated reconnaissance and credential management framework called “Recon.” This tool was found operating on a live command-and-control server, managing more than 23,000 stolen credentials, including API keys for cloud infrastructure and AI services.
Broadening Target Profiles
The threat is no longer limited to specialised AI research laboratories. Government, military, healthcare, and media organisations are increasingly targeted, particularly those that manage proprietary data within Retrieval-Augmented Generation (RAG) pipelines or custom AI workflows.
Recent investigations by Mandiant revealed that threat actors breached a healthcare organisation to steal drug research and a proprietary AI model. In a separate incident, attackers compromised an AI media generation company, stealing proprietary source code, prompts, model scripts, and secrets.
The high cost of premium model access and high-performance compute remains a primary driver for these activities, leading to an increase in the targeting, exfiltration, and sale of AI accounts within cybercrime communities.




Leave a Reply