SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Google warns of AI-powered cyberattacks in live ops

Google warns of AI-powered cyberattacks in live ops

Wed, 9th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Google has reported that cyber threat actors are moving from basic prompting to more autonomous uses of artificial intelligence in live operations, reducing the time available for defenders to respond.

Findings from Google Threat Intelligence Group describe a shift in how espionage groups, cyber criminals and influence operators use AI tools across the attack cycle. The report says attackers are using agent-based workflows, targeting proprietary AI assets and stealing access to paid AI services and cloud computing resources.

One of the clearest examples involved a cloud compromise that led to a mass credential-harvesting campaign in less than six hours. According to Google, the attackers used an AI coding chatbot, a prompt and a set of agent instructions to plan, build and run the operation, while the system handled scanning, troubleshooting and internet protocol rotation with little manual input.

The report also points to rising risks in software supply chains as AI-assisted coding becomes more common. Attackers are increasingly abusing open-source ecosystems, developer tools and AI coding assistants, with incidents spanning package repositories and container registries.

Among the groups highlighted was UNC6780, also known as TeamPCP, which Google linked to large-scale software supply chain compromises across PyPI, npm and Docker Hub. The group used compromised developer accounts, malicious package forks and altered workflows to steal credentials and access proprietary data that could later be sold or used in extortion.

Google says UNC6780 also adapted its malware to interact directly with AI tooling. In some cases, the malware hid files inside project directories associated with coding assistants and development environments, created automated startup or build commands, and used malicious configuration files to push AI assistants into running attacker-controlled scripts.

Another tactic involved attempts to interfere with AI-based security review. The report says the group embedded adversarial prompt text inside JavaScript loader comments in an effort to make large language model security scanners fail or skip analysis of the underlying malicious code.

AI assets

Beyond software supply chains, threat actors are increasingly targeting AI intellectual property. Google cited incidents involving the theft of proprietary models, prompts, source code, scripts and research from organisations in healthcare, government, media and technology.

In one healthcare case investigated by Mandiant, attackers stole drug research and a proprietary AI model before threatening to release the material unless a ransom was paid. In another incident involving a company focused on AI media generation, attackers exfiltrated source code, prompts, skills, model scripts and secrets, then used the data in an extortion attempt.

Google also described growing concern around attacks aimed at extracting model behaviour. It says coordinated distillation campaigns against its own models now occur regularly, with some involving more than 100 million prompts across text, visual, audio and video features. Attackers used proxy systems, compromised credentials and fraudulent accounts to hide the source of the activity.

State groups

The report links AI use to a range of state-backed actors. According to Google, a China-linked espionage group sought to use Gemini to design an automated penetration-testing framework that could observe a target environment, reason through actions and carry out discovery tasks such as port scanning and service parsing.

It also described a separate China-linked group experimenting with AI-assisted development tools to build an automated exploitation and post-exploitation pipeline. In that case, multiple models were queried to write exploit scripts, create spear-phishing lures and debug errors.

Russian and Iranian actors were also cited. Google says a Russia-based group known as UNC5792 experimented with AI models in monitoring bots used to analyse Telegram channels for information of interest to Russian authorities. Iranian operators, meanwhile, used generative AI to create prompts for image generators to build false personas and to draft narratives aligned with state interests.

These activities have not yet produced a major leap in influence operations, but they have improved productivity in areas such as translation, content creation and persona building. Google added that it had not observed interactive AI bot systems being deployed successfully in live influence campaigns.

Account theft

The cost of premium model access and large-scale compute is driving another strand of activity: theft and resale of AI-related accounts. The report says underground demand for credentials tied to Gemini, Claude and coding tools such as Cursor Pro and Devin has risen sharply, with average marketplace prices more than doubling this year.

Infostealer operators have also widened their focus. Rather than only harvesting browser profiles, some are now targeting configuration files used by coding assistants, including files that may contain plaintext API keys and model routing settings.

In one intrusion outlined by Google, a threat actor entered a victim cloud environment through an exposed GitHub personal access token, then enabled enterprise AI services, set up containerised model access tools, provisioned compute instances and sought higher quotas for graphics hardware to sustain unauthorised AI workloads.

Google said it had disrupted several of the campaigns by disabling accounts and other assets tied to the activity, and that observations from these cases had been fed back into model safety systems and internal security controls. “This operation marks a critical evolution in threat actor methodology: a transition from passive, endpoint-focused infostealers to offensive agentic harvesting,” said Google Threat Intelligence Group.