Chinese government hackers have figured out how to run artificial intelligence models on networks they have already broken into, letting them conduct entire intrusion campaigns in under six hours without leaving a trail. Google's Threat Intelligence Group published a quarterly report Tuesday detailing how several Chinese hacking groups have gone from typing prompts into chatbots to deploying fully automated AI agents that do the dirty work for them. The playbook is elegant in the most infuriating way imaginable: hack somebody, borrow their computer, use it to hack somebody else.
What Google Actually Found
According to Google's Threat Intelligence Group, one specific Chinese hacking outfit that Google has tracked since 2023 has spent years going after academic institutions, medical research centers, and military research organizations across North America. The targets are not random. The group has specifically chased proprietary AI research, which means China is using AI tools to steal AI tools. Read that sentence again.
The quarterly report describes a meaningful tactical shift: hacking groups are no longer doing the slow, hands-on keyboard work that traditional cyberespionage requires. Instead, they are layering AI agents into their operations, automating wide swaths of the intrusion process. Google says it clocked some campaigns running from start to finish in less than six hours. A few years ago, that kind of operation might have taken weeks.
The Trick That Makes This So Hard to Catch
Here is the part that should genuinely alarm you. The hackers are not signing up for ChatGPT and typing "how do I hack the Pentagon." That would be logged, flagged, and stopped by content filters before they got anywhere useful. Instead, as Google's chief analyst John Hultquist explained to NBC News, they compromise an unrelated victim's cloud network, install open-source AI models directly on that machine, and run their operations from there.
"They compromise a third party and they put models on that third party. They do that instead of using, say, a commercial option where their activities are observed," Hultquist told NBC News. So the AI they are using has no guardrails, no usage monitoring, and no corporate trust and safety team watching the logs. It is a clean room built inside someone else's house, and the homeowner has no idea.
The practical effect is that China's hackers get all the efficiency benefits of advanced AI without any of the commercial accountability that makes those tools slightly less dangerous. They are not breaking the terms of service. They are running their own instance of open-source software on a server they stole.
They Are Not Just Hacking Faster. They Are Trying to Remove Humans From the Loop.
Google says it has not yet observed a fully automated hacking campaign run entirely by AI agents with no human involvement. That distinction matters, but maybe not as much as you would hope, because Hultquist made clear that is exactly what they are building toward.
"There were a couple cases where we could see them essentially trying to build out autonomous capabilities, so they can remove themselves, remove humans from the loop on some of their most important tasks," Hultquist told NBC News. This is the trajectory: each quarter, a little more automation, a little less human oversight required, a little more scale. You do not need to have fully autonomous AI cyberattacks to find that roadmap concerning.
For context, NBC News notes that both OpenAI and Anthropic have separately reported in recent months that their own AI agents slipped out of controlled evaluation environments and reached third-party organizations by accident. So the frontier AI labs building these tools cannot always keep them contained in sandboxes. China's hackers, who have fewer ethical constraints and zero liability concerns, are building toward the same capabilities on purpose.
The Target List Should Focus Some Minds
Google did not name any of the victims, which is the kind of sentence that makes researchers and hospital administrators very nervous simultaneously. Academic institutions. Medical research organizations. Military research centers. These are not hardened corporate targets with eight-figure security budgets. Universities in particular are notoriously porous, built around open access and collaboration, staffed by people whose primary job is research, not threat detection.
The White House has framed the AI competition with China in terms of who will develop the most powerful systems first. That framing has focused almost entirely on compute, talent, and investment. What Google's report illustrates is that there is a third lane in that race, and China is running in it: steal the research you cannot build fast enough yourself. The U.S. has long accused China of hacking American companies specifically for economic advantage, as NBC News notes, a tactic that Western governments consider out of bounds. The Chinese Embassy's response Tuesday was that China "opposes hacking activities" and rejected what it called "vilification and smears." Standard denial, nothing new.
What Nobody Is Quite Saying Out Loud
The AI race that politicians keep describing as a competition between two nations with different values is also, apparently, a competition between two nations with very different legal constraints on what their hackers are allowed to do. American intelligence agencies have powerful cyberespionage capabilities, as NBC News notes carefully. But American hackers, whether government or private sector, cannot legally install AI on stolen German hospital networks and run six-hour intrusion campaigns against research universities.
China's hackers can, and they are. The question of whether the U.S. is "winning" the AI race gets a lot more complicated when one side is allowed to cheat and has been doing so for years.
The Dingo Take
You are supposed to look at this and think: this is a technical cybersecurity story, interesting but contained, a problem for the experts to sort out. That framing is wrong. What Google documented is a foreign government systematically vacuuming up the American AI research that took billions of dollars and thousands of researchers to produce, and doing it using AI tools running on computers belonging to people who have no idea they are hosting a Chinese intelligence operation. This is industrial theft at a scale and speed that is genuinely new.
The bipartisan panic about TikTok has consumed years of congressional bandwidth over concerns that a Chinese company might harvest American user data. Meanwhile, according to Google, Chinese intelligence has been breaking into academic medical and military research networks since at least 2023 and stealing the actual underlying AI research those institutions spent decades producing. The proportionality of our attention to these two threats is, to put it gently, completely backwards.
And before anyone in Washington uses this report as an excuse to do something stupid and unrelated, like restrict open-source AI models domestically, note that the problem Google is describing is not that open-source models exist. The problem is that American networks are being compromised in the first place. Fix the door before you argue about what kind of lock the neighbors are using.




Comments