AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Google warns AI is enabling less-resourced attackers to achieve nation-state-level capabilities.
Summary
Google's Threat Intelligence Group (GTIG) reports that both criminal and state-sponsored adversaries are increasingly leveraging AI to automate and scale their attacks. This trend, evolving from simple prompt injection to sophisticated AI-driven campaigns, allows smaller threat actors to operate with the reach previously seen only from well-resourced nation-state groups. Examples include rapid credential harvesting and exploitation of open-source supply chains, with actors like TeamPCP (UNC6780) and nation-state groups from China, Iran, and North Korea actively using AI for reconnaissance, malware development, and social engineering.
Full text
Adversaries, both criminal and state-sponsored, are increasingly using AI to automate and scale their attacks, according to Google’s Threat Intelligence Group (GTIG). What started as relatively simple adversarial prompt injection into enterprise AI systems has become a full-blown war, with aggressors developing and using their own AI systems, and enterprises using additional AI defenses that provide an expanded attack surface. It is an ongoing and expanding loop that is unlikely to abate. Google, straddling both sides of this war (partly a cause by developing Gemini, and partly a defense in its efforts to detect and shut down attackers), has chronicled the evolution through 2026. The overall effect of this automation is an increased speed of attack, and TeamPCP (UNC6780) provides an example. “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” say the Google researchers. Harnessing AI allows attackers to operate at a scale more typically associated with larger and better resourced groups, such as those affiliated with nation states. TeamPCP is also used to highlight the growing severity of threat actor exploitation of AI and the open source supply chain. Since March 2026, the actor has conducted such compromises against targets including PyPI, npm, and Docker Hub. It has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices, some of which are embedded within its Dustmaker credential stealer software. TeamPCP also developed Shai-Hulud and Miasma, both of which are publicly available. GTIG believes “The publicity, apparent success, and open-source release of UNC6780’s malware will likely spur adversary emulation of these tactics.”Advertisement. Scroll to continue reading. The group is just one of many actors similarly using AI as a force multiplier for their activities. If a cybersecurity attack is a firefight, AI is fanning the flames. But it’s not just financially motivated criminals taking advantage – nation state actors are also increasingly leaning into AI. In June 2026, GTIG reported on a multi-year cyberespionage campaign by UNC6508, a People’s Republic of China (PRC)-nexus threat actor, targeting academic, medical, and military research institutions in North America. GTIG has also identified various nation-state actors keen on developing offensive agentic AI tools. One PRC group has been seen experimenting with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline. PRC-nexus Basin Castle has been seen querying LLMs to profile high-value targets during early-stage reconnaissance, draft and translate localized social engineering lures, author obfuscated custom malware, and troubleshoot post-exploitation commands. Calanque Ion (aka APT42), an Iran-backed group, has used gen-AI (including Gemini) to identify target email addresses, conduct OSINT research, and translate content across local languages to craft localized pretext lures. Ravine Castle (aka APT24), also PRC-nexus, uses Gemini across the entire attack lifecycle from intelligence gathering to attack capability development, and influence operations. It has also been seen using Gemini to generate politically charged propaganda; research methods on anonymizing data leaks for downstream dissemination to journalists and social media influencers. Midnight Neptune (UNC1069) is a DPRK-nexus actor that has increasingly integrated AI across its operational lifecycles to support cryptocurrency theft. Google’s response to this increase in AI-assisted attacks is to disrupt adversarial operations by disabling associated projects and accounts whenever it identifies them. It also hardens its own models against misuse; for example, “In response to model extraction – or ‘distillation’ – attacks, we have deployed real-time defenses designed to degrade the performance of unauthorized ‘student’ models and detect attempts to clone proprietary logic.” (See here for CISA’s details on China’s distillation attacks against US frontier AI companies.) The basic problem, however, is AI’s facility in finding vulnerabilities and developing new malware and exploits. So long as this persists, bad actors will use AI as a force multiplier for their activities. There will never be a lack of vulnerabilities – as fast as they are located and patched, they are replaced by different vulnerabilities in new software. Good actors such as Google may find and disrupt adversarial activities, but the bad actors will move, adapt and carry on. That has been the pattern in cybersecurity since the internet began – only the details change. AI introduces many more details and adds speed and scale, but the basic warzone is and is likely to remain unchanged. Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours Related: Google DeepMind Unveils Framework to Exploit AI’s Cyber Weaknesses Related: UK Cybersecurity Center Says ‘Deepfakes’ and Other AI Tools Pose a Threat to the Next Election Related: Cyber Insights 2026: Cyberwar and Rising Nation State Threats Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend New Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserThe Hidden Instructions That Can Hijack AI AgentsOpenAI Agents Hijack Another Victim WebsiteOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersCatch Raises $5 Million for AI Executive Assistant With GuardrailsCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 MillionOpenLeash Adds a Human Check to Risky AI Agent Actions Latest News HelmGuard Raises $7.3 Million for Agentic GRC and SecurityAndroid’s September 2026 Updates Patch 180 VulnerabilitiesChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionUS Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsIvanti Patches Critical Flaws Across Enterprise Security Products Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights This Key Will Se
Indicators of Compromise
- mitre_attack — T1593.001
- mitre_attack — T1059.001
- mitre_attack — T1588.002
- mitre_attack — T1071.001
- mitre_attack — T1105