Google Threat Intelligence Group disclosed that a financially motivated hacking group used an autonomous, multi-agent AI framework to run a large-scale credential-harvesting campaign against an enterprise cloud environment, completing the operation in under six hours. The system used an AI coding chatbot along with preconfigured markdown instruction sets as operational playbooks to plan, build, and execute automated vulnerability scanning, credential theft, real-time troubleshooting, and IP-rotation logic with minimal human involvement. Thousands of third-party credentials were exfiltrated before the activity was detected and disrupted.