Google Reports Threat Actors Using AI for Automated Attacks and Credential Theft

Summary
Google's Q2 2026 threat report describes adversaries using AI agents and automation for supply-chain compromises, credential harvesting, espionage, data theft, and unauthorized cloud compute, while targeting proprietary AI assets.
Key points
- GTIG observed a suspected financially motivated actor use a cloud compromise and AI-enabled agents to plan and execute a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials.
- UNC6780 used trojanized MCP tools, compromised repositories, CI/CD tokens, and prompt injection to target AI coding assistants and evade LLM security scanners.
- Threat actors targeted proprietary models, source code, prompts, and research; Mandiant investigated cases involving AI asset theft and extortion.
- GTIG reported recurring model-distillation campaigns exceeding 100 million prompts, using proxies and compromised credentials to target Google's models.
- Actors stole AI credentials and compromised cloud environments to run unauthorized AI workloads; one investigated intrusion began with an exposed GitHub personal access token.
- AI also supported reconnaissance, phishing, malware development, and influence operations, though GTIG said it had not observed fully autonomous exploit pipelines deployed against targets or breakthrough influence-operation capabilities.
- Google said it disrupted actor infrastructure and accounts and strengthened model safeguards and defenses in response to the activity.
Article Details
- Publisher
- Google Cloud / Mandiant
- Report Period
- Q2 2026
- Scope
- Observed adversarial use of AI, AI-asset targeting, software supply chain compromises, and AI-enabled automation, based on GTIG telemetry, Mandiant incident response, threat-actor tracking, and platform defenses.
- Key Statistics
- A campaign observed in Q2 2026 planned, built, and executed mass credential harvesting in under six hours.
- The campaign compromised thousands of third-party credentials; the report does not give an exact count.
- An exposed Recon dashboard was configured to manage over 23,800 harvested secrets.
- Some model-distillation campaigns targeting Google models exceeded 100 million prompts.
- GTIG reported that average underground marketplace prices per AI-related account more than doubled in 2026; no exact prices or sample size were provided.
Threat Actors
APT24Name the report says RAVINE CASTLE was previously known as.APT42Name the report says CALANQUE ION was previously tracked as.BASINName the report says BASIN CASTLE was previously tracked as.BASIN CASTLEPRC-nexus cyber espionage group reported to use generative AI across its attack lifecycle; the report says it was previously tracked as BASIN and TEMP.Hex.CALANQUE IONIranian government-backed actor reported to use AI for reconnaissance, social engineering, and other operations; the report identifies APT42 as a previous tracking name.COULEEName the report says RAVINE CASTLE was previously known as.MIDNIGHT NEPTUNENorth Korea-nexus financially motivated threat cluster reported to use AI in operations supporting cryptocurrency theft; the report says it was formerly tracked as UNC1069.RAVINE CASTLEPRC-nexus cyber espionage group reported to use AI for intelligence gathering, capability development, and influence operations; the report says it was previously known as COULEE and APT24.SandwormName the report says SANDWORM RELIC was formerly known as.ShinyHuntersAlternate name the report gives for UNC6240.TeamPCPExplicitly identified in the report as an alternate name for UNC6780.TEMP.HexName the report says BASIN CASTLE was previously tracked as.UNC1069Name the report says MIDNIGHT NEPTUNE was formerly tracked as.UNC5792Russia-based threat group reported to use AI-enabled monitoring bots to analyze Telegram channels.UNC6240Financially motivated threat cluster reported to conduct high-volume SaaS data exfiltration and extortion; the report also names ShinyHunters as an alternate name.UNC6508PRC-nexus threat actor reported to target proprietary AI research and compromise cloud environments.UNC6780Financially motivated threat actor attributed by the report to large-scale open-source software supply chain compromises and AI-targeting activity.
Malware
ACRStealerof commands issued by controllers of prominent infostealers, including LUMMAC.V2, STEALC.V2, VIDAR, and ACRSTEALER, also showed threat actor interest in stealing AI developer configurations, moving beyond theDUSTMAKERSeveral of these functionalities were embedded within their DUSTMAKER credential stealer malware.LUMMAC.V2Our analysis of commands issued by controllers of prominent infostealers, including LUMMAC.V2, STEALC.V2, VIDAR, and ACRSTEALER, also showed threat actor interest in stealing AI developer configurations, moving beyondShai-HuludUpon successful exploitation and gaining initial access via Phalanx or manual Burp Suite efforts, the actor drops the Shai-Hulud framework onto the compromised hosts.SOMBERMEMEPoisoned internal repository configurations, altered Claude CLI hooks, and deployed the SOMBERMEME backdoor upon developer interaction.STEALC.V2Our analysis of commands issued by controllers of prominent infostealers, including LUMMAC.V2, STEALC.V2, VIDAR, and ACRSTEALER, also showed threat actor interest in stealing AI developer configurations, moving beyondVidarOur analysis of commands issued by controllers of prominent infostealers, including LUMMAC.V2, STEALC.V2, VIDAR, and ACRSTEALER, also showed threat actor interest in stealing AI developer configurations, moving beyond
Vendors
GoogleSince the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting toMandiantGrounded in telemetry from frontline Mandiant incident response engagements, global threat actor tracking, and live platform defenses, this report details how state-sponsored espionage groups, financially motivatedWizby bringing together the reasoning power of Gemini and other frontier models, the risk prioritization of Wiz, the automated remediation capabilities of Gemini and CodeMender, and frontline intelligence from Mandiant.
Products
AI WorkbenchProvisioned an AI Workbench notebook instance to execute retrieval-augmented generation (RAG) pipelines.Artifact RegistryCreated custom Docker repositories in Artifact Registry to build and stage container images for the LiteLLM API and Manus agent framework.BigQueryExecuted targeted BigQuery queries to locate sensitive tables containing environmental variables and additional credentials.ClaudeDUSTMAKER drops or modifies malicious files into hidden project workspace directories for AI coding assistants and integrated development environments (IDEs) (.claude/, .vscode/, .cursor/, etc.).Claude CLIPoisoned internal repository configurations, altered Claude CLI hooks, and deployed the SOMBERMEME backdoor upon developer interaction.ClineIn one command, the actors targeted the secrets.json file of Cline (formerly Claude Dev) and in another targeted the config.yaml file of Continue AI (which was acquired by Cursor in June 2026); these files can storeCloud RunDeployed staged container images to publicly accessible Cloud Run services (exposed via IAM invoker bindings to allUsers) and established firewall rules permitting proxy traffic.CodexTo achieve this, the actor used the tool CC Switch to operate various LLMs, rapidly querying Claude, Gemini, or Codex to write custom exploit scripts, generate convincing spear-phishing lures, or debug errors.Continue AIthe secrets.json file of Cline (formerly Claude Dev) and in another targeted the config.yaml file of Continue AI (which was acquired by Cursor in June 2026); these files can store plaintext API keys, as well asCursor Proon purchasing Claude and Gemini credentials, alongside rising demand for autonomous coding IDEs like Cursor Pro and Devin, reflected in average underground marketplace prices per account more than doubling in 2026.DeepSeek-CoderUsed AI coding assistants such as DeepSeek-Coder to develop Python-based Remote Access Trojans (RATs) incorporating cross-platform persistence, process injection, fileless execution, defense evasion, and C2DevinClaude and Gemini credentials, alongside rising demand for autonomous coding IDEs like Cursor Pro and Devin, reflected in average underground marketplace prices per account more than doubling in 2026.Docker HubSince March 2026, UNC6780 has conducted a series of large scale open source software supply chain compromises targeting ecosystems including PyPI, npm, and Docker Hub.GeminiThese activities triggered Gemini's safety responses, and Google took additional, broader action to disrupt the threat actors' campaigns based on their operational security failures.Gemini 3.8 Flash CyberIn addition to our proactive platform defenses, we’ve recently introduced Gemini 3.8 Flash Cyber, our most capable cybersecurity model with frontier-level performance in vulnerability detection and automated patching.GitHubEvidence indicates that UNC6780 created a malicious GitHub Actions workflow for the company’s proprietary AI repository, and that the extortion actor exfiltrated a copy of this AI repository.GitHub ActionsEvidence indicates that UNC6780 created a malicious GitHub Actions workflow for the company’s proprietary AI repository, and that the extortion actor exfiltrated a copy of this AI repository.Google AI Threat Defenseactivity through proactive disruption of bad actor projects and accounts, and use our autonomous Google AI Threat Defense architecture to operationalize security across enterprise environments.LiteLLMCreated custom Docker repositories in Artifact Registry to build and stage container images for the LiteLLM API and Manus agent framework.ManusCreated custom Docker repositories in Artifact Registry to build and stage container images for the LiteLLM API and Manus agent framework.npmSince March 2026, UNC6780 has conducted a series of large scale open source software supply chain compromises targeting ecosystems including PyPI, npm, and Docker Hub.PyPISince March 2026, UNC6780 has conducted a series of large scale open source software supply chain compromises targeting ecosystems including PyPI, npm, and Docker Hub.
Tools
Burp SuiteThe actor uses Burp Suite, a web application security testing platform, to manually probe the target's web applications, mapping out APIs, identifying vulnerabilities, or testing evasion techniques against webCC SwitchTo achieve this, the actor used the tool CC Switch to operate various LLMs, rapidly querying Claude, Gemini, or Codex to write custom exploit scripts, generate convincing spear-phishing lures, or debug errors.Gemini-CLIIn one observed case, GTIG observed underground actors combining Ghidra with the Gemini-CLI agent to reverse-engineer WinRAR Self-Extracting (SFX) archive components.GhidraIn one observed case, GTIG observed underground actors combining Ghidra with the Gemini-CLI agent to reverse-engineer WinRAR Self-Extracting (SFX) archive components.PhalanxUpon constructing a target profile, the adversary can deploy Phalanx—an open-source, polyglot framework designed for autonomous penetration testing.Reconand Control (C2) server hosting an automated reconnaissance and credential management framework dubbed "Recon." Initial directory listings exposed specialized agentic configuration and knowledge files—includingRubeusResearch Active Directory post-exploitation methods (e.g., Rubeus Kerberos ticket attacks) to elevate permissions and harvest credentials.
Countries
ChinaIn June 2026, GTIG reported on a multi-year cyber espionage campaign by UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting academic, medical, and military research institutions in North America.Democratic People's Republic of Koreaespionage groups; financially-motivated and espionage-related activity attributed to the Democratic People's Republic of Korea (DPRK); financially-motivated cyber crime groups; and state-sponsored IO groups.IndonesiaIranIn Q2, we observed activity aligned with the political interests of China, Iran, and Russia, alongside actors such as commercial spammers and disinfo-for-hire entities.RussiaIn another example, UNC5792—a Russia-based threat group—integrated AI models into automated monitoring bots to analyze Telegram channels for specific information of interest to Russian authorities, such as securityUkraineintelligence gathering, social engineering, and workflow automation in continued operations targeting Ukraine.
Industries
Academic researchCryptocurrencyIn April 2026, public research confirmed an AI coding agent incorporated a malicious cryptocurrency-themed dependency into an active codebase associated with a legitimate cryptocurrency trading project.GovernmentTargeting Proprietary AI IP: GTIG observed increasing instances of adversaries targeting proprietary AI models, code, prompts, and research across sectors including healthcare, government, and media.HealthcareTargeting Proprietary AI IP: GTIG observed increasing instances of adversaries targeting proprietary AI models, code, prompts, and research across sectors including healthcare, government, and media.Media and entertainmentNotably, this targeting was not limited to AI labs or frontier AI companies, as organizations using AI in the government, military, healthcare, and media and entertainment sectors have also been affected.MilitaryNotably, this targeting was not limited to AI labs or frontier AI companies, as organizations using AI in the government, military, healthcare, and media and entertainment sectors have also been affected.TechnologyThis activity affected companies operating in the technology, healthcare, and media and entertainment sectors in North America and Europe.