Threat actors use AI to scale cyberattacks in hours

 

Threat actors use AI to scale cyberattacks in hours

Threat actors are increasingly using artificial intelligence (AI) to speed up cyberattacks, with one financially motivated group carrying out a large-scale credential harvesting campaign in less than six hours, according to Google Threat Intelligence Group (GTIG).

The group, tracked as TeamPCP, used an AI coding chatbot, automated agents and preconfigured instructions to plan and execute the campaign. The operation included automated scanning and credential theft and reportedly compromised thousands of third-party credentials.

GTIG said TeamPCP has also targeted software supply chains, including PyPI, npm and Docker Hub. Its malware includes SANDCLOCK, a Python-based credential stealer designed to run on Linux and interact with Kubernetes, and DUSTMAKER, a JavaScript payload focused on stealing credentials from CI/CD environments.

In August, Australian police and the FBI arrested two men allegedly linked to the TeamPCP cybercriminal group. Authorities said the group stole more than 300 GB of data from over 1,000 organizations and compromised more than 500,000 credentials.

Google said that threat actors are increasingly targeting proprietary AI research, models, and related intellectual property. In particular, China-nexus actor UNC6508 reportedly deployed local, open-weight LLM infrastructure to evade monitoring. In other data-theft operations threat actors were observed stealing models, prompts, skills, source code, and research. Also, threat actors conducted distillation attacks against Google’s AI models, targeting visual and audio understanding, image generation, and video generation capabilities.

Threat actors have been seen experimenting with LLMs to enhance vulnerability research, exploit development, reconnaissance, social engineering, intelligence gathering, and operational automation.

China-nexus groups, including an unnamed government-targeting group, Basin Castle (Mustang Panda), and Ravine Castle (APT24), have used models such as Claude, Gemini, and Codex for exploit scripting, phishing, research, and influence operations.

Russia-linked actors UNC5792 and Sandworm (APT44) have used AI for intelligence gathering, social engineering, and workflow automation. Iran-linked Calanque Ion (APT42) has leveraged generative AI for reconnaissance and targeted social engineering.

North Korean clusters UNC5267 and UNC5342 have used AI in job-fraud and social-engineering operations, while Midnight Neptune (UNC1069) has applied LLMs to social engineering, supply-chain manipulation, and backdoor development.

Financially motivated UNC6240 (ShinyHunters) has used Claude Code to analyze stolen data and evade security controls, while underground actors have combined Ghidra with Gemini-CLI to reverse-engineer WinRAR components.

Back to the list