Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.
Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI models across healthcare, government, and media sectors, exfiltrating API credentials, and co-opting victim cloud environments to sustain unauthorized AI workloads. This highlights growing attacker focus on enterprise AI assets for espionage, extortion, and resource theft.
"At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," John Hultquist, chief analyst at GTIG, said in a statement shared with The Hacker News. "Like everyone else, we're concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary. Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to."
Google noted that the integration of AI-assisted coding tools has not only accelerated software development cycles but also increased threat actors' targeting of developers, AI coding assistants, and LLM security scanning tools, thereby raising open-source supply chain risks.
This has been fueled primarily by a financially motivated threat actor known as TeamPCP (aka Altered Spider and UNC6780), which has conducted a series of large-scale software supply chain compromises targeting PyPI, npm, and Docker Hub. The initial compromise is followed by the deployment of credential stealers like SANDCLOCK and DUSTMAKER to obtain sensitive data and target AI coding assistants, which are then monetized either via direct sale or through partnerships with ransomware and data theft extortion groups.
"DUSTMAKER is a successor to the SANDCLOCK credential stealer in TeamPCP operations," GTIG told The Hacker News. "SANDCLOCK (used in March and April 2026) is a component of what has publicly been referred to as CanisterWorm, was primarily written in Python, and is designed to operate on Linux and interact with Kubernetes. It includes container escape functionality and targeted cryptocurrency wallets in addition to cloud and developer credentials."
"DUSTMAKER (used in April and beyond) is a cross-platform JavaScript payload optimized for CI/CD pipelines. It does not contain container escape functionality, and while some variants have targeted cryptocurrency wallets, its overall focus is credential theft to facilitate extortion operations. The AI-targeting techniques [...] – specifically the poisoning of AI assistant workspaces and the use of prompt injection for defense evasion – are exclusive to DUSTMAKER and were not present in earlier SANDCLOCK variants."
Elsewhere, Google said it detected instances where threat actors are misappropriating proprietary AI research and models -
- A China-nexus threat actor known as UNC6508, which is suspected to have compromised cloud environments to deploy local LLM infrastructure that uses a local, open-weight model, as opposed to a commercial frontier model, thereby evading monitoring by AI model providers.
- Several data theft extortion operations in which threat actors have been observed stealing proprietary AI data, including models, skills, prompts, source code, and related research.
- Threat actors carrying out distillation attacks against Google's AI models that target its visual and audio understanding, image generation, and video generation capabilities.
Adversaries have also been observed ramping up use of agentic AI to facilitate malware and tooling development, with a China-aligned cyber espionage group leveraging Gemini to design and develop an automated penetration testing framework.
"The group sought to build an agentic architecture capable of observing target state, reasoning through actions, and executing tasks in unpredictable environments," Google said. "The planned agent was designed to perform discovery tasks such as port scanning and service parsing, demonstrating an intent to automate initial discovery and execution phases."
Another threat actor found engaging in similar efforts is believed to be financially driven. The activity involved the attackers compromising an unnamed organization's cloud infrastructure to deploy an autonomous, multi-agent attack framework to conduct a credential harvesting operation at scale.
"The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours," Google explained. "Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials."
The integration of AI is said to have allowed the system to autonomously manage the vulnerability scanning pipeline, conduct troubleshooting in real time, and execute IP rotation logic without handholding by a human.
The third category related to adversarial misuse of large language models (LLMs) stems from threat actors experimenting with the technology to augment vulnerability research, prototype exploits, orchestrate complex toolsets, and make tactical decisions on the fly -
- A China-nexus group with a history of targeting government entities has used Claude, Gemini, or Codex to write custom exploit scripts, generate convincing spear-phishing lures, and debug errors.
- The China-nexus cyber espionage group known as Basin Castle (aka Mustang Panda) has used LLMs to assist with tasks ranging from research on high-value targets to troubleshooting errors mid-intrusion.
- The China-nexus cyber espionage group known as Ravine Castle (aka APT24, COULEE, and Pitty Tiger) has used Gemini to conduct intelligence gathering, attack capability development, and influence operations.
- The Russia-based threat group known as UNC5792 has integrated AI models to sift through Telegram channels for specific information of interest to Russian authorities, such as security threats and extremist content.
- The Russian cyber espionage group known as Sandworm (aka APT44 and Sandworm Relic) has used Gemini to support intelligence gathering, social engineering, and workflow automation in continued operations targeting Ukraine.
- The Iranian hacking group known as Calanque Ion (aka APT42) has used generative AI models, including Gemini, to facilitate reconnaissance and targeted social engineering.
- Two North Korean threat clusters, including UNC5267 (aka IT worker fraud scheme), and UNC5342 (aka Contagious Interview) have used AI in their operations, including engaging in bulk LLM API registration using hijacked accounts.
- The North Korea-aligned financially motivated threat actor known as Midnight Neptune (aka UNC1069) has used commercial LLMs and open-weight models for social engineering, software supply chain manipulation, and automated backdoor development.
- The financially motivated threat actor known as UNC6240 (aka ShinyHunters) has used Claude Code to bypass Cloudflare security guardrails and analyze exfiltrated directories for extortion.
- Underground actors have combined Ghidra with the Gemini-CLI agent to reverse-engineer WinRAR Self-Extracting (SFX) archive components.
That's not all. Threat actors have demonstrated an interest in stealing credentials and purchasing capabilities underground to meet their growing demand for AI access. The credentials are likely stolen via information stealer malware like Lumma Stealer, Vidar, and ACR Stealer, which have expanded their capabilities to target AI developer configurations.
Another defining aspect is the hosting of local models on compromised hosts. While Western frontier AI labs have largely restricted access to the advanced cyber capabilities of their most powerful models, rapid improvements in open-weight models' capabilities have also stoked fears that could fuel AI-enabled cyber attacks.
"Open-weight models present an increasing risk by democratizing access and enabling local, unmonitored deployments that lack safety guardrails, particularly with the rise of 'abliterated' or uncensored variants," GTIG told The Hacker News. "While API-gated frontier models allow providers to monitor misuse, open models lack centralized defender visibility, giving threat actors distinct advantages for accelerating tasks like phishing and malicious scripting."
"However, open models also drive essential innovation, so simply gating access is impractical. Enterprise platforms like Gemini Enterprise can provide a contained, safe environment for businesses to leverage open-source models securely. To address this balance, Google formalized its Frontier Safety Framework and Critical Capability Levels (CCLs) to evaluate model capabilities and determine when open deployment poses unacceptable security risks."
"Mitigating these threat actor capabilities ultimately requires establishing enforceable, industry-wide safety baselines specifically for open-source AI, alongside coordinated platform policies to restrict uncensored checkpoints and raise the barrier to entry for adversaries.






