ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Google Threat Intelligence: Adversarial AI Moves From Prompting to Autonomous Agents, Enabling Sub-Six-Hour Credential Theft and Scaled Nation-State Operations

mediumThreat actorexploited in the wildimportance 68
What's new: First merged summary of this story. GTIG's Q2 2026 report newly documents adversaries operating agentic AI workflows rather than simple prompting, including an agent-driven campaign that harvested and validated 23,800+ secrets in under six hours via the Recon C2 dashboard, UNC6780/TeamPCP's ongoing PyPI, npm, and Docker Hub supply chain campaign with DUSTMAKER and the trojanized tiktoken_mcp…
Merged summary · glm-5.3 · rewritten as coverage arrives

GTIG's Q2 2026 AI Threat Tracker documents adversaries adopting agentic AI workflows — including an autonomous campaign that harvested and validated over 23,800 stolen secrets in under six hours, TeamPCP/UNC6780 supply chain attacks on PyPI, npm, and Docker…

Google Threat Intelligence Group's Q2 2026 report traces adversaries evolving from basic LLM prompting to agentic AI workflows and automation. In one documented incident, financially motivated attackers compromised trusted cloud infrastructure and used AI coding agents guided by written playbook files to autonomously perform vulnerability scanning, credential harvesting, troubleshooting, and IP rotation — completing a mass credential theft campaign in under six hours. An exposed command-and-control dashboard for a framework called Recon organized and validated more than 23,800 stolen secrets in real time, including API keys for cloud and AI services. The report tracks financially motivated actor UNC6780 (TeamPCP), which since March 2026 has conducted large-scale open source supply chain compromises across PyPI, npm, and Docker Hub, deploying the DUSTMAKER credential stealer (which hides in .claude, .vscode, and .cursor workspace directories to trigger scripts via workspace config) and publishing the trojanized tiktoken_mcp package on PyPI to target developer and CI/CD tokens; SecurityWeek additionally attributes released tools Shai-Hulud and Miasma to the group. GTIG warns AI now gives lesser-resourced criminal and nation-state attackers nation-state-level speed and scale: PRC-nexus Basin Castle uses LLMs for target profiling, lure drafting, and malware development; APT42 (Calanque Ion) uses Gemini for OSINT and localized lures; APT24 (Ravine Castle) uses Gemini across the full attack lifecycle; and DPRK's Midnight Neptune (UNC1069) integrates AI into cryptocurrency theft. The report also highlights growing targeting of proprietary AI models, source code, prompts, and API credentials, plus LLMJacking, in which adversaries steal developer credentials or hijack cloud infrastructure to run unauthorized AI workloads. Google says it is responding by disrupting attacker accounts and hardening models against distillation/extraction attacks.

  • GTIG's Q2 2026 AI Threat Tracker documents adversaries moving from prompting to agentic AI workflows and automation.
  • Attackers used AI coding agents guided by written playbook files to autonomously handle vulnerability scanning, credential collection, troubleshooting, and IP rotation, completing a mass credential harvesting campaign in under six hours.
  • An exposed C2 dashboard for a framework called Recon organized and validated more than 23,800 stolen secrets in real time, including API keys for cloud and AI services.
  • Compromised trusted cloud infrastructure made attacker traffic appear legitimate and hindered detection.
  • UNC6780 (TeamPCP), financially motivated, has compromised open source supply chains across PyPI, npm, and Docker Hub since March 2026, deploying credential stealers.
  • TeamPCP published the trojanized tiktoken_mcp package on PyPI to target developer and CI/CD tokens.
  • The DUSTMAKER credential stealer hides in .claude, .vscode, and .cursor workspace directories and abuses workspace config to trigger scripts.
  • SecurityWeek attributes the released tools Shai-Hulud and Miasma to TeamPCP.

Coverage timeline

  1. · 7d ago
    Google Threat Intelligence· 65
    GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

    GTIG's Q2 2026 tracker shows adversaries adopting agentic AI workflows, including credential harvesting in under six hours and supply chain attacks by UNC6780.