Google Threat Intelligence Group (GTIG) published an update to its AI Threat Tracker examining the evolution of adversarial AI use from simple prompting toward more autonomous capabilities. The publication focuses on how threat actors may increasingly apply AI systems in malicious operations.
The update highlights autonomous adversarial AI as an emerging security concern for enterprise defenders. CISOs should track AI-enabled threat activity, evaluate controls around AI-agent permissions and tool access, and ensure detection and incident-response processes account for increasingly automated attacker workflows.

Track how attackers are adapting to this technology.
21 events from the most recent confirmed update back to the earliest known activity.
Since April 2026, TeamPCP has used the cross-platform JavaScript payload DUSTMAKER in supply-chain compromises, particularly against CI/CD pipelines. DUSTMAKER steals credentials for extortion operations, and variants can poison AI-assistant workspaces and use prompt injection for defense evasion.
Financially motivated TeamPCP (Altered Spider/UNC6780) used the Python-based SANDCLOCK credential stealer, also known publicly as CanisterWorm, in campaigns targeting PyPI, npm, and Docker Hub. The malware targeted Linux and Kubernetes environments, including cryptocurrency wallets, cloud credentials, and developer credentials.
Lumma Stealer, Vidar, and ACR Stealer expanded their targeting to AI developer configurations.
UNC6240, also known as ShinyHunters, used Claude Code to bypass Cloudflare security guardrails and analyze exfiltrated directories for extortion.
Midnight Neptune, also known as UNC1069, used commercial LLMs and open-weight models for social engineering, software supply-chain manipulation, and automated backdoor development.
North Korean clusters UNC5267 and UNC5342 used AI in their operations, including bulk registration of LLM APIs using hijacked accounts.
Calanque Ion, also known as APT42, used generative AI models including Gemini for reconnaissance and targeted social-engineering activity.
Sandworm, also tracked as APT44 and Sandworm Relic, used Gemini for intelligence gathering, social engineering, and workflow automation in operations targeting Ukraine.
Russia-based threat group UNC5792 used AI models to sift Telegram channels for material of interest to Russian authorities, including security threats and extremist content.
Ravine Castle, also known as APT24, COULEE, and Pitty Tiger, used Gemini for intelligence gathering, attack-capability development, and influence operations.
Basin Castle, also known as Mustang Panda, used LLMs for high-value target research and troubleshooting during intrusion operations.
A China-nexus group targeting government entities used Claude, Gemini, or Codex to create exploit scripts, generate spear-phishing lures, and debug errors.
Google stated that it disabled assets associated with the observed autonomous credential-harvesting campaigns and updated its protections after the actors made operational-security mistakes.
Google Cloud researchers identified an exposed Recon command-and-control server used by the autonomous credential-theft operation. Its dashboard was designed to organize, validate, and manage more than 23,800 stolen secrets, including API keys for cloud and AI services.
A financially motivated actor compromised an unnamed organization's cloud infrastructure and used an autonomous multi-agent framework to harvest thousands of third-party credentials in under six hours. The framework scanned targets, rotated IP addresses, troubleshot in real time, and was planned and executed with an AI coding chatbot, prompts, and agent instructions.
A China-aligned cyber-espionage group used Gemini to design an automated penetration-testing framework intended to conduct port scanning and service parsing.
Threat actors conducted distillation attacks against Google's AI models to obtain visual and audio understanding, image-generation, and video-generation capabilities.
GTIG observed data-extortion operations stealing proprietary AI models, skills, prompts, source code, and research materials.
China-nexus actor UNC6508 was suspected of compromising cloud environments to deploy locally hosted LLM infrastructure based on open-weight models.
GTIG observed threat actors targeting proprietary AI models in the healthcare, government, and media sectors, including through theft of AI API credentials and abuse of victim cloud environments for unauthorized AI workloads.
GTIG reported that TeamPCP developed the publicly available Shai-Hulud and Miasma malware. The group also embedded some of its AI-tool and open-source-development exploitation methods in its DUSTMAKER credential stealer.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityweek.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourcethehackernews.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.