Autonomous AI cyberattacks: the moment the threat became permanent
Autonomous AI cyberattacks are end-to-end hacking operations in which AI agents independently plan, adapt, and execute intrusions in real time, mapping networks, exploiting vulnerabilities, stealing data, and modifying infrastructure without needing step-by-step human control or preprogrammed playbooks. This is no longer theory; suspected China-linked hackers used publicly available AI tools to run what researchers describe as the first fully autonomous cyberattack against a government, compromising at least 85 user accounts and stealing more than 2,500 personnel records. The attackers built their platform from open-source AI-agent frameworks that let multiple agents simultaneously map systems, research vulnerabilities, attempt intrusions, and change strategy when paths failed. Dream’s chief strategy officer warns that the arrival of this tooling means every government should now assume it is under permanent automated assault, not facing isolated incidents.

From discrete hacks to continuous, adaptive AI cyberattacks
The key change is not that attackers use AI, but that AI now drives the entire operation. In the observed government attack, the autonomous hacking system mapped 21 government systems before compromising accounts and extracting personnel information, then expanded to nuclear safety systems, energy companies, suppliers, and other targets. Its most alarming feature was the ability to continuously devise attacks on its own: the platform assessed evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, it tasked another agent with searching the internet for fresh information and creating an alternative approach. That is real-time strategy adaptation at machine speed. Instead of an operator manually steering each move, AI malware and agents can coordinate multi-stage campaigns across networks, turning what used to be a series of events into a steady, automated siege.
How AI turns intruders into autonomous strategists
State-linked and criminal operators are using AI not just to accelerate tasks, but to outsource thinking. In one case, an attacker used Claude Code, running an advanced model, to generate and execute reconnaissance and exploitation commands, write malicious scripts, modify firewall policies, and analyze business systems to identify those most relevant to a ransomware operation. According to Gambit Security, the AI examined domain controllers, file servers, backup servers, application databases, and backup infrastructure to highlight the most valuable targets. At one victim, the operator asked which databases mattered most; the AI ranked them and pointed to the live production database and client document store. This is not a helper that occasionally writes code; it is an embedded strategist that guides where to move next, which files to steal, and how to manage the technical infrastructure during active intrusions.

Credential theft AI and lateral movement at scale
Traditional perimeter defenses crumble when credential theft AI turns every exposed file into a potential master key. In another case, a threat actor built auto_scan, a tool that searches the internet for unintentionally exposed sensitive files and open directories containing API keys, tokens, and other credentials. The scanner downloads accessible files or directory listings and combs them for credentials tied to AI providers, cloud services, servers, and SaaS platforms, then validates candidate credentials against the relevant services. Auto_scan itself was created with OpenAI Codex and Claude Code, with instructions framed as an “authorized CTF sandbox” to bypass safety rules. Between early April and late May, this operation collected 2,975 validated keys and credentials from 1,742 victim hosts. Once attackers automate finding and validating credentials, lateral movement is no longer a painstaking process; it becomes a scaled, industrial workflow that perimeter-focused security cannot contain.
Why AI malware means permanent assault, not occasional risk
The uncomfortable truth is that AI cyberattacks have changed the basic physics of security. AI tools now write malicious code, build credential-harvesting frameworks, search compromised networks, identify valuable business information, manage technical infrastructure, and generate commands during intrusions. Custom Python attack frameworks have been observed scanning internet-facing services, exploiting vulnerable deployments, harvesting credentials, and deploying cryptocurrency miners, with many scripts likely AI-generated. On the government side, open-source AI agent systems such as Hermes and OpenClaw were assembled into an autonomous toolkit that continuously devised attack strategies. When safeguards triggered, attackers simply reframed their activity as authorized testing to make models comply. The result is a threat landscape where both state-sponsored groups and criminal hackers can run nonstop, self-improving campaigns. Security teams are no longer defending against clever individuals but against tireless machine swarms. Treat autonomous hacking as a permanent, automated assault, or accept that your defenses are already behind the curve.





