GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
Google Threat Intelligence Group reports that adversaries in Q2 2026 rapidly advanced from basic AI prompting to agentic workflows, using AI for mass credential harvesting, supply chain compromise, and attacks on proprietary AI assets. The report also details UNC6780’s open source supply chain operations, multiple nation-state and cybercrime groups abusing Gemini across the attack lifecycle, and Google’s mitigations against misuse. #UNC6780 #DUSTMAKER #Gemini #UNC6508 #UNC5792 #SANDWORMRELIC #BASINCASTLE #CALANQUEION #RAVINECASTLE #MIDNIGHTNEPTUNE #UNC6240 #OutsiderEnterprise

Keypoints

  • Adversaries are moving from simple prompting to agentic AI workflows and automation, sharply reducing defender response time.
  • GTIG observed a cloud resource compromise followed by planning and execution of a mass credential harvesting campaign in under six hours.
  • UNC6780 (TeamPCP) conducted large-scale open source supply chain compromises targeting PyPI, npm, and Docker Hub, using credential stealers and extortion follow-on activity.
  • DUSTMAKER used hidden workspace files, prompt injection, and CI/CD abuse to manipulate AI coding assistants and evade security checks.
  • Threat actors increasingly target proprietary AI models, prompts, source code, credentials, and cloud compute resources for espionage and extortion.
  • Multiple state-linked and financially motivated groups used generative AI for reconnaissance, phishing lures, malware development, vulnerability research, and post-exploitation automation.
  • Google says it responded by disabling abusive assets, strengthening safety classifiers, and deploying defenses such as Google AI Threat Defense and Gemini 3.8 Flash Cyber.

MITRE Techniques

  • [T1195.001] Supply Chain Compromise – UNC6780 trojanized legitimate developer assets and published compromised packages and MCP tools (‘published trojanized forks of legitimate MCP servers’ / ‘inject malicious code directly into official organizational GitHub repositories’).
  • [T1552.001] Credentials In Files – ACRSTEALER targeted AI assistant configuration files that can store plaintext API keys (‘secrets.json file of Cline’ and ‘config.yaml file of Continue AI’).
  • [T1555] Credentials from Password Stores – Actors harvested developer and platform credentials from compromised environments and AI tools (‘collects credentials to AI tools alongside other credentials’).
  • [T1078] Valid Accounts – Threat actors used stolen developer credentials and hijacked accounts to access AI platforms and cloud resources (‘stealing developer credentials’ / ‘purchasing compromised AI platform accounts’).
  • [T1059.001] PowerShell – BASIN CASTLE used PowerShell for post-exploitation troubleshooting (‘Troubleshoot PowerShell errors for Active Directory domain discovery post-exploitation’).
  • [T1059.004] Unix Shell – SANDWORM RELIC and others used scripts and shell automation for credential spraying and lateral movement (‘write and refine asynchronous Python scripts’ / ‘draft Bash scripts’).
  • [T1059.006] Python – Attackers used Python to automate exploitation, credential harvesting, and post-exploitation tasks (‘asynchronous Python scripts designed to perform automated password spraying’).
  • [T1059.007] JavaScript – DUSTMAKER used JavaScript loader scripts with embedded prompt injection (‘prompts embedded as comments at the top of the malware’s JavaScript loader scripts’).
  • [T1027] Obfuscated Files or Information – Threat actors used obfuscation in malware, code, and AI-generated content (‘author obfuscated custom malware’ / ‘extreme adversarial text’).
  • [T1036] Masquerading – DUSTMAKER disguised malicious pipeline tasks as legitimate AI utilities (‘disguised under AI-themed names such as “Copilot Setup”’).
  • [T1204] User Execution – Malicious prompts and workspace hooks relied on developer interaction to trigger execution (‘whenever the assets were downloaded or cloned’ / ‘during routine developer interactions’).
  • [T1053.005] Scheduled Task/Job: Container and CI/CD Automation – DUSTMAKER created automated build/startup commands and CI/CD tasks to persist and execute (‘automated build or startup commands’ / ‘compromised CI/CD environments’).
  • [T1566] Phishing – Several groups used AI to craft spear-phishing lures and social engineering content (‘generate convincing spear-phishing lures’ / ‘craft localized pretext lures’).
  • [T1110.003] Password Spraying – SANDWORM RELIC wrote scripts for automated password spraying (‘write and refine asynchronous Python scripts designed to perform automated password spraying’).
  • [T1595] Active Scanning – Actors deployed agentic frameworks to scan targets and identify services (‘perform discovery tasks such as port scanning and service parsing’).
  • [T1580] Cloud Infrastructure Discovery – Adversaries queried cloud environments and quotas to identify resources (‘Executed targeted BigQuery queries’ / ‘request quota increases’).
  • [T1090] Proxy – Attackers used proxies and IP rotation to obscure origin and route traffic (‘route traffic through the proxies’ / ‘implement obfuscation tactics including automated routing through proxies’).
  • [T1219] Remote Access Software – UNC6240 used Claude code and MCP tools to parse exfiltrated directories and support extortion operations (‘Integrating Claude code configured with custom Model Context Protocol (MCP) tools’).
  • [T1041] Exfiltration Over C2 Channel – Several operations involved exfiltrating AI repositories, data, or secrets for extortion (‘exfiltrated a copy of this AI repository’ / ‘stole corporate data and drug research’).
  • [T1021] Remote Services – Threat actors leveraged cloud services and GitHub Actions runners for remote execution and access (‘GitHub Actions runners’ / ‘Cloud Run services’).

Indicators of Compromise

  • [File names] Malicious workspace, loader, and config artifacts used for persistence or prompt injection – tiktoken_mcp, azure-functions-mcp-extension, _index.js, AGENTS.md, KNOWLEDGE.md, agentic_vuln_research.md
  • [File paths / directories] Hidden AI workspace directories and configuration stores abused by DUSTMAKER and others – .claude/, .vscode/, .cursor/, .openclaw/, memory/
  • [Cloud / platform artifacts] Compromised developer and CI/CD artifacts used to publish malicious packages or persist access – GitHub Actions, GitHub repositories, Artifact Registry, Cloud Run, AI Workbench
  • [Package ecosystems] Open source ecosystems targeted for supply chain compromise – PyPI, npm, Docker Hub
  • [Account / token types] Credentials and tokens harvested from cloud and AI environments – OIDC tokens, GitHub Personal Access Token (PAT), API keys, service account keys
  • [Malware / tooling names] Malware and offensive frameworks referenced in the article – DUSTMAKER, LUMMAC.V2, STEALC.V2, VIDAR, ACRSTEALER, Phalanx, Shai-Hulud, Recon, SOMBERMEME
  • [AI / service names] AI tools and services abused or targeted – Gemini, Claude, Cursor Pro, Devin, Cline, Continue AI, DeepSeek-Coder
  • [Organizations / campaigns] Threat clusters and operations named in the article – UNC6780 (TeamPCP), UNC6508, UNC5792, UNC6240 (ShinyHunters), BASIN CASTLE, CALANQUE ION, RAVINE CASTLE, SANDWORM RELIC, MIDNIGHT NEPTUNE, Outsider Enterprise


Read more: https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai/