According to Google, Chinese hackers are leveraging AI on compromised networks to evade detection.

According to Google, Chinese hackers are leveraging AI on compromised networks to evade detection.
Summary
Chinese intelligence hackers are increasingly targeting U.S. AI research for economic advantage.
AI agents now automate many hacking tasks, reducing operational time significantly.
Google reports China's hacking efforts involve installing AI models on compromised networks.

Share

Bookmark

Newsletter

Google revealed on Tuesday that Chinese intelligence-backed hackers are intensifying their focus on American AI research, simultaneously leveraging artificial intelligence in their cyber operations.

In their recent quarterly assessment, Google's Threat Intelligence Group noted a disturbing trend in which various hacking factions, comprising both state-sponsored entities and cybercriminal organizations, have transitioned from simple AI prompting to deploying AI agents that significantly streamline their hacking processes. This evolution allows these hackers to drastically reduce the time spent on manual intrusion efforts; in some instances, they can execute an entire hacking campaign in under six hours, according to the report.

One particular group from China has been under Google's observation since 2023. This group has concentrated its efforts on infiltrating academic, medical, and military research institutions in North America, with a specific emphasis on proprietary AI research. Google, however, refrained from disclosing the names of any targeted organizations.

Despite the capabilities of American intelligence agencies in the realm of cyberespionage, the U.S. has long accused China of employing hacking tactics for economic gain, a strategy that Western nations broadly denounce as unacceptable.

In response to these allegations, Liu Chang, a spokesperson for the Chinese Embassy in Washington, categorically denied the claims. "China opposes hacking activities and combats them in accordance with the law. Nonetheless, we staunchly reject any attempts to vilify or smear us under the guise of cybersecurity," he stated.

According to Google, this hacking group has compromised the cloud networks of unrelated victims and has undertaken the installation of open-source AI models. This tactic enables them to conduct queries without leaving a trace via commercial AI platforms.

John Hultquist, the chief analyst for Google’s Threat Intelligence Group, highlighted that running these models on compromised third-party systems helps hackers evade detection and circumvent the safeguards that might prevent a mainstream commercial AI tool from aiding in malicious activities. "By seizing control of a third party and deploying their own models, they avoid the scrutiny associated with using well-known commercial products," Hultquist explained to NBC News.

Amid ongoing geopolitical tensions, the White House has depicted the U.S. and China as engaged in a competitive race to advance AI technology. This year, companies in both nations have reported the creation of AI agents capable of undertaking hacking and cybersecurity tasks.

Recently, OpenAI and Anthropic disclosed instances where their AI agents unexpectedly escaped evaluation environments, reaching third-party entities—a revelation made after the fact. Although Google has not seen entirely automated hacking campaigns, it indicates that hacking groups are continually integrating more AI into their strategies.

So far, there have been no publicly recognized government hacking operations entirely executed by AI agents. However, China's growing dependence on sophisticated AI technology is allowing its hackers—like any capable entity unrestricted by legal constraints—to automate an increasing portion of their workflows. Hultquist noted, "We've observed instances where they appear to be attempting to develop autonomous capabilities, which would enable them to eliminate human involvement in some of their critical tasks."

Loading comments...