ZeroHour
Story · 1 source · 1 articlefirst updated ()

Google Warns Autonomous AI Agents Enabled Mass Credential Theft in Under Six Hours and Give Lesser-Resourced Attackers Nation-State-Level Reach

mediumThreat actorexploited in the wildimportance 68
What's new: This is the first merged summary for this story (no previous summary existed). It combines two same-day reports (2026-09-09) on Google's threat intelligence findings: Cyber Security News' coverage of the sub-six-hour autonomous agent credential theft campaign (23,800+ secrets, Recon C2, tiktoken_mcp, DUSTMAKER) and SecurityWeek's broader GTIG assessment of AI-enabled threat actors…
Merged summary · glm-5.3 · rewritten as coverage arrives

Google threat intelligence reports that attackers used autonomous AI coding agents guided by playbook files to harvest and validate more than 23,800 stolen secrets in under six hours, part of a broader 2026 trend in which AI gives lesser-resourced criminal…

Google Cloud threat intelligence and Google's Threat Intelligence Group (GTIG) documented financially motivated attackers compromising cloud infrastructure and deploying autonomous AI coding agents guided by written playbook files to scan, harvest, troubleshoot and rotate credentials within six hours. A command-and-control dashboard for a framework called Recon organized and validated more than 23,800 stolen secrets, including API keys for cloud and AI services; the agents autonomously handled vulnerability scanning, credential collection, troubleshooting and IP rotation, while compromised trusted cloud infrastructure made attacker traffic appear legitimate and hindered detection. SecurityWeek attributes the campaign to TeamPCP, which GTIG tracks as UNC6780 — the same cluster Cyber Security News links to publishing the trojanized tiktoken_mcp package on PyPI targeting developer and CI/CD tokens. TeamPCP has compromised the PyPI, npm, and Docker Hub supply chains since March 2026 with its Dustmaker credential stealer, which hides in .claude, .vscode and .cursor workspace directories to trigger scripts via workspace configuration, and has released the tools Shai-Hulud and Miasma. Beyond TeamPCP, GTIG documented throughout 2026 that other adversaries increasingly use AI: PRC-nexus Basin Castle uses LLMs for target profiling, lure drafting and malware development; APT42 (Calanque Ion) uses Gemini for OSINT and localized lures; APT24 (Ravine Castle) uses Gemini across the full attack lifecycle; and DPRK's Midnight Neptune (UNC1069) integrates AI into cryptocurrency theft. Google says it is responding by disrupting attacker accounts and hardening models against distillation attacks.

  • Google observed attackers using autonomous AI coding agents, guided by written playbook files, to complete a mass credential harvesting campaign in under six hours.
  • A Recon C2 dashboard organized and validated more than 23,800 stolen secrets in real time, including API keys for cloud and AI services.
  • AI agents autonomously performed vulnerability scanning, credential collection, troubleshooting and IP rotation.
  • Compromised trusted cloud infrastructure made attacker traffic appear legitimate and hindered detection.
  • The actor is tracked as UNC6780, also named TeamPCP by GTIG; it distributed the trojanized tiktoken_mcp package on PyPI targeting developer and CI/CD tokens.
  • TeamPCP has compromised PyPI, npm, and Docker Hub supply chains since March 2026 with the Dustmaker credential stealer, which hides in .claude, .vscode and .cursor workspace directories to trigger scripts via workspace config.
  • TeamPCP has also released tools named Shai-Hulud and Miasma.
  • GTIG attributes TeamPCP's activity as using an AI coding chatbot with agent instructions to plan and execute the credential harvesting campaign.

Coverage timeline

  1. · 7d ago
    Cyber Security News· 58
    Hackers Use Autonomous AI Agents to Launch Mass Credential Theft Attacks in Under 6 Hours

    Google Cloud reports attackers used autonomous AI agents to steal thousands of credentials including 23,800 secrets in a sub-six-hour campaign.