Google’s Threat Intelligence Group says adversaries are increasingly using AI to automate attacks, accelerate credential theft, and scale exploitation across the open-source supply chain. Nation-state-linked groups such as UNC6780, UNC6508, APT42, APT24, and UNC1069 are also leveraging AI for reconnaissance, malware development, social engineering, propaganda, and theft. #UNC6780 #UNC6508 #APT42 #APT24 #UNC1069 #Gemini #Dustmaker #PyPI #npm #DockerHub #ShaiHulud #Miasma
Keypoints
- AI is being used by both criminal and state-sponsored actors to speed up attacks.
- UNC6780 used an AI coding chatbot to run a credential-harvesting campaign in under six hours.
- Threat actors are targeting the open-source supply chain, including PyPI, npm, and Docker Hub.
- PRC-, Iran-, and DPRK-linked groups are using AI for reconnaissance, malware writing, and influence operations.
- Google is countering with account takedowns and defenses against model extraction and misuse.