Google Finds Chinese Hackers Running AI on Compromised Networks

Google says China-linked hackers are running AI inside compromised cloud environments, using victims’ computing power while reducing outside monitoring.

Written By
LT
Liz Ticong
Sep 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Suspected China-linked hackers are running AI models inside cloud environments they have already breached.

Google Threat Intelligence Group suspects UNC6508, a China-linked espionage group that has targeted North American academic, medical, and military research organizations, carried out the activity.

Earlier investigations found the same group maintaining access to some research networks for more than a year. 

A local AI model kept the workload inside the victim’s cloud

Suspected operators deployed an open-weight AI model directly inside compromised cloud environments, according to the latest GTIG AI threat research. In plain terms, they installed a downloadable model that could run on the victim’s computing resources instead of sending requests to an outside AI service.

Running it locally let the attackers use computing power they did not own and avoid some monitoring available through commercial AI services. Detection then depended more heavily on the victim’s own cloud security controls.

According to researchers, UNC6508 has also targeted proprietary AI research, connecting the cloud activity to the group’s wider interest in AI. 

Long-term access shows how UNC6508 operates

An earlier Google investigation of UNC6508 traced attacks against North American research organizations back to 2023. Operators repeatedly targeted REDCap systems used for medical and scientific research and, in one documented compromise, installed custom malware called INFINITERED to harvest credentials and survive software upgrades.

Some intrusions remained undetected for more than a year. Stolen credentials later gave the attackers access to an enterprise administrator account, where they abused legitimate email rules to quietly forward selected messages to an attacker-controlled account. 

The attackers also routed activity through US-based infrastructure to make malicious traffic harder to distinguish from normal use.

Google later disrupted infrastructure tied to the campaign and notified affected organizations.

Advertisement

Research security teams should treat unexplained cloud use as suspicious

For universities, medical research centers, and similar organizations, unusual cloud activity should be investigated as a possible security issue, not only a cost problem. Research environments already consume significant computing resources, so unauthorized AI workloads may be easier to overlook.

  • Trace unusual compute to a known owner. Sudden GPU use, new cloud servers, or unexpected cost increases should map to an approved project and user. Unexplained activity deserves a security review.
  • Review what a compromised account changed. Resetting a password does not remove workloads or settings created before the account was secured. Check for new servers, scheduled jobs, administrator changes, and unfamiliar email-forwarding rules.
  • Look beyond login alerts. Valid credentials can make attacker activity appear legitimate. Cloud workload security monitoring can help identify activity that falls outside normal use even when authentication looks routine.
  • Contain access before removing attacker resources. Revoke active sessions and rotate exposed credentials before cleanup. Strong access controls can reduce the chance that compromised identities are used again.

Finding stolen credentials should widen the investigation. Security teams need to determine whether information was accessed, settings were changed, or cloud resources were used after the breach.

More news: An AI-assisted WeChat exploit could spread from one compromised contact to another, putting a platform with more than a billion users at potential risk.

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.