GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
Google Cloud Threat Intelligence warns that adversaries are weaponizing AI agent workflows to automate attacks, including credential harvesting and supply-chain compromises, reducing defender response time.
Google Threat Intelligence Group reports that threat actors have shifted from simple AI prompting to deploying autonomous agent workflows, enabling rapid execution of attacks such as mass credential harvesting within hours. In Q2 2026, adversaries compromised a cloud resource and executed a credential harvesting campaign in under six hours, demonstrating how AI automation compresses traditional attack timelines. The group also tracked UNC6780 using deceptive tactics to trick AI coding assistants and LLM security scanners into compromising open-source software supply chains. These operations highlight the growing sophistication of adversaries in exploiting AI tools to accelerate and scale their attacks.
Google Cloud Threat Intelligence identifies proprietary AI models, source code, and cloud compute resources as high-value targets for espionage, extortion, and resource theft. Adversaries are increasingly targeting AI assets, including model weights and API credentials, to sustain unauthorized AI workloads within victim environments. The report notes a rise in incidents where threat actors co-opt cloud infrastructure to run high-performance compute workloads without authorization. This trend underscores the expanding attack surface created by the integration of AI into enterprise environments.
The report details how state-sponsored groups, cyber criminals, and information operations actors are operationalizing AI tools across the attack lifecycle, from reconnaissance to post-exploitation. Threat actors are experimenting with scaling information operations campaigns and using AI as a force multiplier in multi-stage attacks. Google emphasizes its commitment to responsible AI development, integrating model-level safeguards, threat intelligence, and autonomous defense mechanisms to protect customers and infrastructure. The company highlights its proactive disruption of malicious projects and accounts to mitigate emerging threats.
Google Cloud Threat Intelligence highlights the increased risks in software supply chains due to AI-assisted coding tools and open-source software integration. The report cites examples of malicious open-source AI resources detected in enterprise environments and instances where AI coding agents incorporated malicious dependencies into legitimate projects. Threat actor UNC6780 has conducted large-scale supply-chain compromises targeting ecosystems like PyPI, npm, and Docker Hub since March 2026, deploying credential stealers and monetizing stolen data. The report warns that these tactics are likely to inspire further adversary emulation.