New research from the Google Threat Intelligence Group reveals that threat actors are deploying artificial intelligence across an expanding range of cyberattack phases, including reconnaissance, penetration testing, credential theft and post-intrusion troubleshooting. Drawing upon Mandiant investigations, proprietary threat intelligence, observed misuse of Gemini and activity across the criminal underground, the GTIG AI Threat Tracker indicates that adversaries are pairing artificial intelligence with automation to amplify both the speed and scale of their operations.

In one of the incidents, Mandiant observed an autonomous credential-harvesting campaign orchestrated through a multi-agent framework hosted on stolen infrastructure. The automated system compromised thousands of credentials within six hours while managing several operational elements independently. Beyond credential harvesting, state-sponsored operators are exploring similar technologies to refine their intrusions. A PRC-linked cyber espionage collective attempted to utilise Gemini to construct an automated penetration-testing framework capable of executing the initial phases of a compromise. Meanwhile, BASIN CASTLE, another cyber espionage group tied to the PRC, relied on large language models for tasks spanning target research to live troubleshooting during active intrusions.

AI systems are becoming targets

Hostile groups are increasingly shifting their attention towards the underlying infrastructure, data and software that support enterprise AI systems. Mandiant has investigated multiple intrusions across North America and Europe affecting organisations in technology, healthcare, as well as media and entertainment, where proprietary AI models and data were explicitly targeted. In several of these cases, extortionists threatened to publish the exfiltrated assets unless a ransom was paid.

The threat extends directly into the software supply chain that feeds corporate development. Google identified coordinated attempts to compromise the broader ecosystem, including activity by TeamPCP, an entity that tampered with tools used by AI coding assistants and poisoned open-source package information to ensure developers were directed towards malicious dependencies. Malware associated with the group featured covert prompts engineered to execute commands without the developer’s knowledge. Because AI coding assistants actively engage with external packages and developer resources, these poisoned dependencies establish an insidious entry point into private software environments.

Attackers seek access to AI computing resources

Beyond software and proprietary data, adversaries are actively pursuing the high-performance computing resources and credentials required to power modern models. GTIG observed threat actors acquiring system credentials and purchasing access on illicit underground forums, while several actors deployed local AI models directly onto compromised networks. Running models locally enables threat groups to carry out malicious tasks while bypassing the safety guardrails and monitoring mechanisms enforced by commercial AI providers.

Recent investigations highlight how widespread this resource exploitation has become across different threat actors. UNC6508, a PRC-linked group responsible for an intrusion campaign against medical facilities in the United States, leveraged compromised cloud environments to host a local AI model. In an April 2026 investigation, Mandiant identified an adversary that exploited unauthorised access to establish bespoke AI infrastructure, provisioning expensive, high-performance GPU capacity entirely at the victim’s expense. In another instance, Google tracked an activity cluster of DPRK-linked IT workers who systematically hijacked genuine accounts to register numerous large language model API profiles.

John Hultquist, Chief Analyst at Google Threat Intelligence Group, observed that combining artificial intelligence with automated processes could drastically curtail the time defenders have to react. “At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited. Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary. Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to.”

“In order to scale, and get their hands on AI resources, threat actors will steal it. Even cyber espionage actors like UNC6508 are willing to use compromised systems. That actor used a local model as well, allowing it to avoid commercial monitoring.”

“There is a new generation of threat actor, like TeamPCP, that will target AI systems as we incorporate them into our tech stack. For now, the supply chain is their primary interest, but it’s clear that they will seek other opportunities.”

The incidents documented by GTIG significantly widen the defensive perimeter that enterprise security teams must safeguard as artificial intelligence adoption accelerates. Proprietary models, sensitive credentials, third-party software dependencies and underlying computing hardware have all emerged as prime targets, even as adversaries harness AI to automate and accelerate conventional intrusion techniques.

Share