Artificial Intelligence

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.

AI attack

Adversaries, both criminal and state-sponsored, are increasingly using AI to automate and scale their attacks, according to Google’s Threat Intelligence Group (GTIG).

What started as relatively simple adversarial prompt injection into enterprise AI systems has become a full-blown war, with aggressors developing and using their own AI systems, and enterprises using additional AI defenses that provide an expanded attack surface. It is an ongoing and expanding loop that is unlikely to abate.

Google, straddling both sides of this war (partly a cause by developing Gemini, and partly a defense in its efforts to detect and shut down attackers), has chronicled the evolution through 2026.

The overall effect of this automation is an increased speed of attack, and TeamPCP (UNC6780) provides an example. “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” say the Google researchers.

Harnessing AI allows attackers to operate at a scale more typically associated with larger and better resourced groups, such as those affiliated with nation states.

TeamPCP is also used to highlight the growing severity of threat actor exploitation of AI and the open source supply chain. Since March 2026, the actor has conducted such compromises against targets including PyPI, npm, and Docker Hub. It has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices, some of which are embedded within its Dustmaker credential stealer software.

TeamPCP also developed Shai-Hulud and Miasma, both of which are publicly available. GTIG believes “The publicity, apparent success, and open-source release of UNC6780’s malware will likely spur adversary emulation of these tactics.”

Advertisement. Scroll to continue reading.

The group is just one of many actors similarly using AI as a force multiplier for their activities. If a cybersecurity attack is a firefight, AI is fanning the flames. But it’s not just financially motivated criminals taking advantage – nation state actors are also increasingly leaning into AI.

In June 2026, GTIG reported on a multi-year cyberespionage campaign by UNC6508, a People’s Republic of China (PRC)-nexus threat actor, targeting academic, medical, and military research institutions in North America.

GTIG has also identified various nation-state actors keen on developing offensive agentic AI tools. One PRC group has been seen experimenting with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline. 

PRC-nexus Basin Castle has been seen querying LLMs to profile high-value targets during early-stage reconnaissance, draft and translate localized social engineering lures, author obfuscated custom malware, and troubleshoot post-exploitation commands.

Calanque Ion (aka APT42), an Iran-backed group, has used gen-AI (including Gemini) to identify target email addresses, conduct OSINT research, and translate content across local languages to craft localized pretext lures.

Ravine Castle (aka APT24), also PRC-nexus, uses Gemini across the entire attack lifecycle from intelligence gathering to attack capability development, and influence operations. It has also been seen using Gemini to generate politically charged propaganda; research methods on anonymizing data leaks for downstream dissemination to journalists and social media influencers.

Midnight Neptune (UNC1069) is a DPRK-nexus actor that has increasingly integrated AI across its operational lifecycles to support cryptocurrency theft.

Google’s response to this increase in AI-assisted attacks is to disrupt adversarial operations by disabling associated projects and accounts whenever it identifies them. It also hardens its own models against misuse; for example, “In response to model extraction – or ‘distillation’ – attacks, we have deployed real-time defenses designed to degrade the performance of unauthorized ‘student’ models and detect attempts to clone proprietary logic.” (See here for CISA’s details on China’s distillation attacks against US frontier AI companies.)

The basic problem, however, is AI’s facility in finding vulnerabilities and developing new malware and exploits. So long as this persists, bad actors will use AI as a force multiplier for their activities. There will never be a lack of vulnerabilities – as fast as they are located and patched, they are replaced by different vulnerabilities in new software. Good actors such as Google may find and disrupt adversarial activities, but the bad actors will move, adapt and carry on. That has been the pattern in cybersecurity since the internet began – only the details change. AI introduces many more details and adds speed and scale, but the basic warzone is and is likely to remain unchanged.

Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours

Related: Google DeepMind Unveils Framework to Exploit AI’s Cyber Weaknesses

Related: UK Cybersecurity Center Says ‘Deepfakes’ and Other AI Tools Pose a Threat to the Next Election

Related: Cyber Insights 2026: Cyberwar and Rising Nation State Threats

Related Content

Compliance

The company will increase its US market presence and will expand its engineering and go-to-market teams.

Artificial Intelligence

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

Artificial Intelligence

Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.

Artificial Intelligence

Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.

Artificial Intelligence

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.

Artificial Intelligence

Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access.

Artificial Intelligence

New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.

Artificial Intelligence

The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version