Security.io Intelligence DeskWednesday, 9 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
AI Security · Executive briefing

GTIG observes agent-enabled credential harvesting at cloud scale

GTIG says a financially motivated operator used a bespoke multi-agent framework from compromised cloud infrastructure to harvest thousands of third-party credentials in under six hours, while a separate Recon framework managed more than 23,800 secrets.

AI SecurityIdentityCloud Security
Why it is in today’s brief

GTIG’s September 8 report materially advances earlier discussion of adversarial AI by documenting an observed cloud-hosted, under-six-hour credential campaign and exposing a separate Recon framework managing more than 23,800 secrets. It warrants inclusion because the new decision is operational: govern agents as privileged automation and instrument cloud control planes for their effects. It ranks fifth because victims, models and complete detection artefacts remain unpublished.

Read first

Govern agent frameworks as privileged automation, monitor cloud control planes for unauthorised scanning and secret-management workloads, and shorten credential revocation paths to match compressed attack timelines.

Act now

Inventory agents, cloud identities, tools, secrets and network permissions.

Accountable owner

CISO with cloud security, identity, AI governance, development-platform and incident-response leaders

Decision horizon

Today: review cloud and AI control-plane privileges; within 30 days establish governed inventories for agents, secrets, tool permissions and anomalous automation.

AssessmentMedium confidence
Emerging riskVictim disclosures, framework artefacts, detection rules, underlying-model attribution, cloud-provider enforcement data or independently confirmed campaign scale.

What happened

Google published the GTIG report on September 8, 2026. In Q2 2026, GTIG observed a compromised cloud resource used to plan, build and execute an agent-enabled mass credential-harvesting campaign in under six hours. GTIG says the campaign compromised thousands of third-party credentials. Operating from the victim cloud environment allowed the attacker to route scanning through legitimate infrastructure.

The cited sources identify an unnamed bespoke multi-agent attack framework and a separate framework dubbed Recon. The underlying model and version for the under-six-hour credential-harvesting framework were not identified in the cited sources. The operator configured an AI coding chatbot with a prompt, agent instructions and preconfigured markdown instruction sets used as operational playbooks. The configured system scanned infrastructure, harvested credentials, troubleshot failures and rotated IP addresses with reduced human intervention.

GTIG identified a separate framework dubbed Recon with AGENTS.md, KNOWLEDGE.md and agentic_vuln_research.md files, .openclaw/ and memory/ directories, and a dashboard managing more than 23,800 harvested secrets. The reported secrets included API keys for cloud and AI services. This observation was separate from the unnamed under-six-hour campaign and should not be treated as the same framework or operator without additional evidence.

The cited sources did not publish the affected organisation, framework hashes, IP addresses, domains or a complete detection package for the under-six-hour campaign. Attribution posture: GTIG describes the operator as a suspected financially motivated threat actor and does not name a group. GTIG says its assessment draws on Mandiant incident response, threat-actor tracking and platform defences, but the public report does not permit independent victim-level verification.

Why this matters now

The reported activity compresses planning, construction, troubleshooting and scaled credential collection into a single operating window. Defenders relying on manual hand-offs between cloud, identity and incident-response teams may lose the opportunity to contain activity before a campaign reaches thousands of credentials. Detection and revocation need machine-speed paths even when investigative conclusions remain human-governed.

Compromised cloud infrastructure gave the operator legitimate IP space and elastic capacity. That weakens simple reputation-based controls and makes cloud account governance part of external attack prevention. Organisations should monitor sudden scanning patterns, public-service deployment, IP rotation, secret validation and abnormal API consumption from identities that normally support development or analytics.

The report also shows that AI-specific assets are now both tools and targets. Framework instruction files, coding-assistant workspaces, API keys and cloud quotas can become part of an attack pipeline. Security leaders should govern the authority and observable effects of agents rather than attempt to classify risk solely by model brand or claimed autonomy.

The decision for security leaders

Place agent frameworks and AI coding automations inside privileged-access governance. Record the operator, instructions, tools, credentials, accessible networks, data stores and permitted external effects. Approval should depend on authority and consequence, not whether the automation is marketed as an assistant or agent.

Monitor cloud control planes for behaviour associated with attack infrastructure: unexpected public endpoints, rapid provisioning, secret-management dashboards, scanning traffic and privilege expansion. Development subscriptions and sandbox projects require the same identity and egress scrutiny as production when they can reach external targets or store enterprise secrets.

Shorten the credential-containment loop. High-confidence detections should support automated suspension or constrained rotation for API keys and service identities, with human review governing broader business impact. A six-hour campaign window leaves little room for ticket-based escalation chains.

Evidence of closure

  • Agent register identifies every authorised framework, operator and connected tool.
  • Cloud detections validate coverage for unauthorised scanning and secret aggregation.
  • Credential tests prove emergency suspension and rotation paths function.
  • Privilege review removes unapproved public-service and control-plane permissions.

The Security.io assessment

The report provides credible evidence that operators are moving beyond one-off chatbot prompts into configured workflows that execute multiple attack tasks. It does not establish that a model independently selected the objective or acted without operator design. The operator supplied the prompt, instructions, playbooks and compromised infrastructure; the system mechanically accelerated execution.

In the activity GTIG observed, the configured system scanned infrastructure, harvested credentials, troubleshot failures and rotated IP addresses. Security programmes should respond to the observed speed and scale of that workflow while keeping assessments tied to the reported mechanics.

Recon’s exposed artefacts provide useful architecture clues, but no complete public indicator set exists for the under-six-hour campaign. Detection should therefore emphasise observable cloud and identity effects: unusual scanning, secret aggregation, credential testing, public-service creation, privilege changes and abnormal API use. Model identification is secondary to controlling the authority granted to the workflow.

Questions for the morning meeting

  • Which enterprise cloud identities can provision public services or high-cost compute?
  • Are AI-development workspaces monitored for hidden instruction and credential files?
  • Can security teams distinguish authorised automation from agent-driven scanning?
  • Which AI and cloud credentials lack workload baselines or rapid revocation?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →