North Korea, China, Iran Ship AI Agents Into Real Cyberwar
State-backed hackers are no longer testing AI in labs. Google's Threat Intelligence Group documents Chinese, Iranian, and North Korean groups deploying autonomous AI agents for live credential theft, phishing, and supply-chain attacks—marking a decisive shift in cyber warfare.
AI agents are no longer academic exercises. They are on the job.
Google’s Threat Intelligence Group released its quarterly AI Threat Tracker report on June 9, and the headline finding is blunt: nation-state hackers from China, Iran, and North Korea have moved past proof-of-concept demos and laboratory sandboxes into live, operational use of autonomous AI agents. The shift is not incremental. It is structural.
The report documents attack lifecycles now embedding AI at multiple stages—reconnaissance, weaponization, credential harvesting, and post-exploitation—rather than relying on AI for a single task like code generation or phishing email drafting. That distinction matters because it changes the scale and tempo of operations. An agent that can manage its own scan pipeline, self-heal errors, and rotate between tasks without human intervention does not just speed up an attack. It expands the number of attacks a single operator can run simultaneously.
This represents a fundamental reordering of how cyber campaigns operate. Where traditional ops required dozens of specialists coordinating across time zones, a handful of analysts can now direct systems that sustain themselves. The bottleneck is no longer human labor. It is access to models and infrastructure.
How the Chinese groups are using AI
Two China-affiliated spy networks appeared prominently in the GTIG findings.
The group known as BASIN CASTLE deployed large language models across the full kill chain. Its operators used AI for target profiling in the early reconnaissance phase, generated social-engineering bait documents and translated them for tailored lures, wrote obfuscated custom malware, and then relied on LLMs during post-exploitation to troubleshoot command issues in real time. Each stage is something a skilled operator could do manually. Combining them under AI automation compresses the timeline dramatically.
The implications extend beyond speed. When AI manages its own workflow, it reduces the human signatures that defenders traditionally track—typing patterns, tool choices, communication rhythms. The operators themselves become harder to attribute because their digital fingerprints are diluted across automated processes.
Another China-linked group attempted to build a Gemini-based agentic framework for automated simulated penetration testing—a system that plans and executes attack steps autonomously rather than following a static playbook. The report suggests the framework was aimed at the initial intrusion phase, which means these actors are treating AI as an operational multiplier, not a research curiosity.
In one documented case, a Chinese-affiliated operator stole cloud infrastructure, deployed an agentic AI system on it, and harvested thousands of credentials in six hours. The speed alone signals a transition from manual brute-force techniques to AI-driven credential enumeration at scale. But the second-order effect is more concerning: those credentials did not exist in a vacuum. They likely cascaded into lateral movement across partner networks, vendor ecosystems, and interconnected enterprise environments—turning a six-hour strike into days of ongoing compromise.
Iran’s CALANQUE ION runs AI across the entire operation
The Iran-linked group CALANQUE ION applied generative AI models to a wider set of functions than any other actor described in the report. Its workflow included identifying target email addresses, conducting open-source intelligence gathering, producing multilingual phishing bait, summarizing leaked data, developing tactical infrastructure, and attempting software reverse engineering.
That breadth is noteworthy. Most reported AI-assisted attacks focus on one or two capabilities, typically phishing or malware generation. CALANQUE ION appears to be running a semi-autonomous AI pipeline from target selection through post-exploitation analysis. The implication is that a small team can sustain prolonged campaigns without proportional increases in headcount.
The multilingual dimension of CALANQUE ION’s operations deserves particular attention. By generating phishing content in multiple languages with native-level fluency, the group effectively expands its hunting ground beyond English-speaking targets into Southeast Asia, the Middle East, and Eastern Europe—regions where security awareness programs and incident-response maturity vary significantly. This geographic diversification forces defenders to monitor threat landscapes they may have previously considered low-risk.
North Korea scales through API abuse
North Korea’s involvement took a different but equally significant form. The report observed that North Korean IT worker organizations—state-directed groups that lease cyber talent to foreign clients—mass-registered LLM API accounts using compromised credentials to expand their operational capacity. Rather than building custom AI tools, they purchased access at scale and applied it to their campaigns.
This pattern is likely to repeat. As commercial AI APIs become cheaper and more accessible, the barrier to entry for AI-augmented cyber operations drops further. North Korea’s approach reflects a pragmatic strategy: buy computing power instead of building it, and redirect savings toward human operators and infrastructure.
The scale of the credential-compromise operation itself is a warning. Mass account registration using stolen credentials indicates that North Korean groups have already penetrated corporate identity systems at significant volume. Those same credentials are likely being used not only for AI API access but also for secondary purposes—accessing proprietary datasets, exploiting enterprise software licenses, or maintaining persistent footholds in customer environments.
The supply-chain angle is the sleeper risk
Perhaps the most underreported finding in the GTIG report concerns software supply-chain risk. AI-assisted coding tools are accelerating development velocity, but they are also increasing dependence on third-party packages and open-source libraries that receive less rigorous security review. The report directly links this trend to a rise in software supply-chain compromise incidents.
Nation-state actors are now targeting AI assets themselves—proprietary models, source code, API credentials—as part of broader campaigns. There are also indications that attackers are hijacking victim cloud environments to run unauthorized AI workloads, effectively stealing compute capacity to fuel their own operations.
This creates a compound threat: compromised software spreads wider and faster, and the AI infrastructure that modern enterprises depend on becomes both a target and a weapon. When an AI model trained on sensitive enterprise data is exfiltrated, the damage extends beyond the immediate breach—the model itself may encode proprietary logic, customer information, or operational patterns that competitors or adversaries can exploit independently.
The supply-chain risk operates on two levels. First, AI-generated code may introduce vulnerabilities at scale, as operators rush to integrate large volumes of machine-written functions without adequate review. Second, nation-state actors are increasingly targeting the repositories and model registries where that code lives, turning the acceleration of development into an acceleration of contamination.
What changes next
John Hultquist, GTIG’s senior analyst, summarized the trajectory plainly: every threat actor is now using AI, and the effect is measurable. The danger is not that AI introduces a single new vulnerability. The danger is that AI agents make existing attack patterns larger, faster, and more persistent.
The practical consequence for organizations is straightforward. Security teams that still treat AI as a future risk are already behind. The transition from lab to production has happened. Defenses need to account for autonomous AI agents that can reconfigure themselves, rotate infrastructure, and operate across time zones without sleep.
This requires moving beyond signature-based detection toward behavioral monitoring that can identify anomalous automation patterns. It means assuming that credential stores are continuously targeted by AI-driven enumeration and that any sensitive code committed to version-control systems carries supply-chain risk. Organizations should also audit their AI API access aggressively—unauthorized or bulk API registrations are now a known indicator of North Korean operational activity.
Korean security firms have been tracking some of these developments closely, and GTIG’s report validates what the regional intelligence community has suspected: the Asian theater is where state-sponsored AI cyber operations are advancing fastest, driven by the resources and urgency of well-funded programs in Beijing, Tehran, and Pyongyang. Western incident-response teams will likely see these tactics migrate to their environments within quarters, not years.
The report’s clearest signal is that the window between experimental deployment and operational deployment has effectively closed. Nation-state actors are not preparing to use AI agents in cyber warfare. They are using them now, and the cadence of their campaigns is accelerating as each group learns from the others’ deployments.