
Google says China-linked hackers now run artificial intelligence inside the very networks they’ve already stolen—so the alarms never trip.
Story Snapshot
- Google’s threat team reports China-linked groups using on-target AI to hide and speed attacks.
- Targets include American academic, medical, and military research, with focus on proprietary AI.
- Attackers route traffic through trusted cloud and hijacked systems to blend in.
- This continues a long pattern of stealthy Chinese cyber espionage, now supercharged by AI.
Google flags a shift: AI agents on victim networks
Google’s Threat Intelligence Group reports that several China-linked hacking teams moved from basic prompts to full AI agents that run on compromised systems. These agents help plan intrusions, write and tweak code, and troubleshoot in real time without sending suspicious requests off the victim’s network.
That matters because traditional defenses look for odd outbound traffic and strange tools. If the model runs inside your walls, your tools may see normal activity while attackers map and move.
NBC News summarized the report as a clear trend: hackers use on-target artificial intelligence to speed up every step of the attack. The groups include intelligence services and criminal crews with ties to China.
The teams use artificial intelligence to build better lures, scan for weak points, and manage stolen credentials at scale. That reduces the time from first break-in to data theft. It also cuts their mistakes, which defenders often rely on to catch intruders early.
Chinese hackers are running AI on stolen networks to avoid detection, Google says
One China-linked group targets academic, medical and military AI research, the report sayshttps://t.co/ZRMtKlIwML— Emily Turrettini (@textually) September 8, 2026
Who they hit and why it matters now
One China-linked group tracked since 2023 focused on research institutions in the United States and Canada. The group went after academic, medical, and military research, including high-value artificial intelligence projects, for more than a year before exposure.
The campaign ran from September 2023 to November 2025 and sought proprietary research data. That aim lines up with broader goals seen for years: collect intellectual property, learn how systems work, and gain leverage in future crises.
Stealth remains the throughline. Chinese cyber actors have a record of quiet persistence, living off the land, abusing cloud accounts, and using valid credentials to look like regular users.
Mandiant, a Google company, has chronicled this steady push for years, including jumps to zero-day exploits, compromised routers, and supply chain entry points that leave fewer footprints.
Artificial intelligence slots into that playbook as a force multiplier. It scales reconnaissance, code tweaks, and movement without adding noise that triggers alerts.
How attackers blend in and beat alarms
Attackers now route traffic through known-good cloud services and even use hijacked cloud projects to launder activity. Google has previously disrupted China-linked infrastructure built on commercial cloud, which shows how often spies piggyback on trusted platforms. The new twist is artificial intelligence operating inside the victim network.
That allows continuous scanning, automatic privilege checks, and quick fixes when scripts fail, all while using local compute that looks like normal business load. Defenders then face a ghost that moves fast and rarely slips.
Google’s threat team also warned that state-backed groups from the People’s Republic of China are pushing artificial intelligence into earlier and later phases of the kill chain: from crafting near-perfect phishing to exfiltrating data with smart throttling that mimics normal use. Some reporting describes attackers using artificial intelligence to find flaws that common scanners miss and to help build exploits faster.
What to do next: concrete steps that work
Leaders should assume artificial intelligence will run on their networks—by them or by an intruder. Make it a policy to inventory where models can execute and who can deploy them.
Lock down service accounts and enforce multi-factor authentication, especially for cloud and identity providers. Monitor for drift in workload behavior, not just signatures. Baseline identity use and alert on impossible travel and rare admin actions. Test data egress controls against slow-and-low transfers.
Public and private sectors should also align incentives. President Trump’s administration has leaned on resilience and deterrence through strength. That approach applies here. Reward fast patching on critical software. Penalize vendors who hide material security gaps.
Expand information sharing that gives small and mid-size firms access to real indicators, not vague tips. Push for clear red lines on state-backed theft of research. America wins when we protect our talent, guard our tools, and make spying costly for those who target our innovation.
Sources:
nbcnews.com, reuters.com, gigazine.net, blog.google, bleepingcomputer.com, euronews.com














