ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Google GTIG Warns of Autonomous AI Agents in Cyberattacks as Six-Hour Credential Heist Signals Shift to Agentic Operations

mediumThreat actorexploited in the wildimportance 72
What's new: This is the first merged summary for the story. The new developments are GTIG's AI Threat Tracker documenting adversaries' evolution from prompting to agentic, multi-step AI attack workflows — most notably a sub-six-hour credential harvesting campaign run without human intervention and validated by an exposed Recon C2 dashboard holding over 23,800 secrets — alongside UNC6780's (TeamPCP) ongoing…
Merged summary · glm-5.3 · rewritten as coverage arrives

Google Threat Intelligence documents adversaries moving from AI prompting to autonomous multi-agent attacks — including a sub-six-hour campaign that harvested thousands of credentials and a C2 dashboard holding 23,800+ secrets — while Okta finds stolen AI…

Google Threat Intelligence Group's (GTIG) AI Threat Tracker, drawing on Mandiant incident response and platform telemetry, documents adversaries shifting from basic prompting to agentic AI workflows and automation (reports disagree on the edition's label: Help Net Security cites a Q3 2026 tracker while GTIG's own report is labeled Q2 2026). In the standout case, a financially motivated actor compromised trusted cloud infrastructure and used an AI coding chatbot guided by agent instructions and playbook files to autonomously run vulnerability scanning, troubleshooting, and IP rotation, harvesting thousands of third-party credentials in under six hours without human intervention; an exposed C2 dashboard for a framework called Recon organized and validated more than 23,800 stolen secrets, including cloud and AI service API keys. Related activity attributes to TeamPCP (UNC6780, aka Altered Spider), which has conducted open source supply chain compromises across PyPI, npm, and Docker Hub since March 2026, deploying the SANDCLOCK and DUSTMAKER credential stealers — DUSTMAKER abuses hidden .claude, .vscode, and .cursor workspace directories, poisons AI assistant workspaces, and uses prompt injection for defense evasion — and published the trojanized tiktoken_mcp package on PyPI to target developer and CI/CD tokens; TeamPCP has also released the tools Shai-Hulud and Miasma. PRC-nexus espionage actors UNC6508 and Basin Castle (Mustang Panda) used local open-weight LLMs in compromised clouds to evade AI provider monitoring and commercial LLMs including Gemini, Claude, and Codex for tasks such as target profiling, lure drafting, and malware development. Other tracked actors include APT42 (Calanque Ion) using Gemini for OSINT and localized lures, APT24 (Ravine Castle) using Gemini across the full attack lifecycle, and DPRK's Midnight Neptune (UNC1069) integrating AI into cryptocurrency theft. Adversaries are also targeting proprietary AI models in healthcare, government, and media — exfiltrating model weights, source code, prompts, and API credentials — and practicing LLMJacking by stealing developer credentials or hijacking cloud environments to run unauthorized AI workloads; distillation attacks targeted Google's image, video, and audio AI capabilities, and Google says it is disrupting attacker accounts and hardening models against extraction. Complementary Okta analysis of a 7 GB infostealer dump dated August 2, 2026, covering 5,871 infected machines in 162…

  • A financially motivated actor harvested thousands of third-party credentials in under six hours using an autonomous multi-agent framework, with AI agents handling vulnerability scanning, troubleshooting, and IP rotation without human…
  • An exposed Recon C2 dashboard organized, managed, and validated over 23,800 stolen secrets in real time, including API keys for cloud and AI services.
  • TeamPCP (UNC6780, aka Altered Spider) has conducted supply chain compromises across PyPI, npm, and Docker Hub since March 2026, deploying the SANDCLOCK and DUSTMAKER credential stealers and releasing the tools Shai-Hulud and Miasma.
  • DUSTMAKER hides in .claude, .vscode, and .cursor workspace directories, poisons AI assistant workspaces, and uses prompt injection for defense evasion; UNC6780 also published the trojanized tiktoken_mcp package on PyPI targeting developer…
  • PRC-nexus actors UNC6508 and Basin Castle (Mustang Panda) used local open-weight LLMs in compromised clouds to evade AI provider monitoring, and commercial LLMs (Gemini, Claude, Codex) for espionage tasks including target profiling, lure…
  • APT42 (Calanque Ion) uses Gemini for OSINT and localized pretexting lures; APT24 (Ravine Castle) uses Gemini across the full attack lifecycle; DPRK's Midnight Neptune (UNC1069) integrates AI into cryptocurrency theft operations.
  • Distillation attacks targeted Google's image, video, and audio AI capabilities; Google says it is disrupting attacker accounts and hardening models against distillation/extraction attacks.
  • Okta's analysis of a 7 GB infostealer dump dated August 2, 2026 (5,871 infected machines across 162 countries) found 555 of 44,791 JWTs related to AI services, 1,843 unexpired JWTs/JWEs largely set by OpenAI via NextAuth.js, and 24…

Coverage timeline

  1. · 7d ago
    Help Net Security· 62
    Threat actors are giving AI agents a bigger role in cyberattacks

    Google Threat Intelligence's Q3 2026 tracker shows threat actors using AI agents for autonomous credential harvesting, including a six-hour campaign compromising thousands of credentials.

  2. · 7d ago
    The Hacker News· 72
    Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Google's GTIG reports threat actors using autonomous AI agents, credential stealers, and LLMs to steal AI models, API credentials, and harvest thousands of credentials.