As cyberattacks become increasingly sophisticated, a new threat has emerged that’s giving lesser-resourced attackers nation-state-level reach: Artificial Intelligence (AI). According to Google’s Threat Intelligence Group (GTIG), adversaries are leveraging AI to automate and scale their attacks, rendering traditional security measures ineffective.
Google’s GTIG has been tracking the evolution of AI-assisted attacks, which started with relatively simple adversarial prompt injection into enterprise AI systems. However, aggressors have since developed and deployed their own AI systems, while enterprises rely on additional AI defenses that provide an expanded attack surface. This ongoing loop is unlikely to abate anytime soon.
One notable example of AI-facilitated attacks is TeamPCP (UNC6780), a threat actor that leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in under six hours. This level of speed and scale is typically associated with larger and better-resourced groups, such as those affiliated with nation-states.
What’s even more concerning is that TeamPCP has exploited the open-source supply chain, compromising targets like PyPI, npm, and Docker Hub since March 2026. The actor has implemented multiple methods to target or exploit AI tools and open-source software development practices, some of which are embedded within its Dustmaker credential stealer software.
TeamPCP’s success has not gone unnoticed, as GTIG believes that the publicity surrounding their tactics will likely spur other adversaries to emulate them. This is particularly alarming, given that nation-state actors are increasingly leaning into AI to further their interests. For instance, in June 2026, GTIG reported on a multi-year cyberespionage campaign by UNC6508, a People’s Republic of China (PRC)-nexus threat actor targeting academic, medical, and military research institutions in North America.
Other nation-state actors are also experimenting with AI-powered tools to build an automated exploitation pipeline. For example, PRC-nexus Basin Castle has been seen querying Large Language Models (LLMs) to profile high-value targets, draft social engineering lures, author malware, and troubleshoot post-exploitation commands. Meanwhile, Calanque Ion (aka APT42), an Iran-backed group, has used gen-AI to identify target email addresses, conduct OSINT research, and translate content across local languages.
To combat these AI-assisted attacks, Google is disrupting adversarial operations by disabling associated projects and accounts whenever it identifies them. The company is also hardening its own models against misuse, deploying real-time defenses designed to degrade the performance of unauthorized “student” models and detect attempts to clone proprietary logic.
However, the fundamental problem remains: AI’s facility in finding vulnerabilities and developing new malware and exploits. As long as this persists, bad actors will continue to use AI as a force multiplier for their activities. There will never be a lack of vulnerabilities – as fast as they are discovered, new ones emerge. To stay ahead of these threats, organizations must adopt a proactive approach to security, incorporating AI-powered defenses that can detect and respond to emerging threats in real-time.
For individuals, the takeaway is clear: being aware of the risks associated with AI-assisted attacks is essential. By staying informed about the latest threats and best practices, you can take steps to protect yourself from these evolving cyber dangers.
Source: SecurityWeek — 2026-09-09