Google said on Tuesday that hackers working for the Chinese Communist intelligence agency are running artificial intelligence (AI) on stolen networks to avoid detection.
According to a report by NBC, Google stated that a Chinese hacker group, which the company has been tracking since 2023, continues to target academic, medical, and military research organizations in North America, especially focusing on proprietary AI research.
Google observed that this hacker group would infiltrate the cloud networks of some unrelated victims and install open-source AI models, a method that allows them to avoid leaving traces of their activities.
John Hultquist, the Chief Analyst of Google’s Threat Intelligence Team, told NBC News that running these AI models on compromised third-party systems allows hackers to evade detection and bypass certain security measures, which might have otherwise prevented popular commercial chatbot services from aiding in hacker attacks.
“They first compromise a third party and then put the AI model onto that third party’s system. They do this because they don’t want to use commercial AI services, as their activities would be monitored when using these services,” Hultquist said.
He mentioned that China is increasingly relying on AI agents installed on hacked computer networks, enabling Communist hackers to automate more tasks. In several instances, they are seen trying to establish autonomous capabilities, reducing the need for human involvement in some critical missions.
Google’s Threat Intelligence Team highlighted in their latest report that multiple hacker groups, including intelligence agencies and cybercriminal organizations, have progressed from instructing AI to perform certain tasks to having AI agents autonomously carry out a series of network infiltration operations.
The report stated that this shift means hackers are significantly reducing the time spent physically executing network attacks. By switching to AI agents, in some cases, they can complete entire attack operations in less than six hours.
A spokesperson from the Chinese Embassy in the United States, Liu Chang, denied these allegations. He stated that China opposes cyberattacks and firmly rejects defamation and slander under the guise of cybersecurity.
The United States and other Western countries have long accused China of infiltrating international companies to gain economic advantages and deem such practices unacceptable.
In a report released in June of this year, Google’s Threat Intelligence Team revealed that between September 2023 and November 2025, hackers extensively collected sensitive information related to national defense intelligence, Indo-Pacific military strategies, artificial intelligence (AI), autonomous vehicle systems, cyber attack projects, and medical research.
Google attributed this cyber espionage operation to an emerging hacker group named “UNC6508.” Luke McNamara, the Deputy Chief Analyst of Google’s Threat Intelligence Team, pointed out that the group’s tactics closely align with years of observed Chinese hacker activities, with a primary focus on gathering intelligence that would pique the interest of the Chinese government.
