news.mlab.sh
Back to the feed
threat-intel

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

High
Summary

Google warns that AI is dramatically expanding the reach and capabilities of both criminal and nation-state attackers. Teams like TeamPCP (UNC6780), linked to China, are leveraging AI to automate attacks, including credential harvesting and malware development, and are releasing tools like Shai-Hulud and Miasma to encourage emulation. Nation-state actors, including those linked to China and Iran, are increasingly utilizing AI across their attack lifecycles for espionage and influence operations. Google is actively responding by disrupting AI-assisted attacks and hardening its own models against misuse, but the underlying problem – AI’s ability to rapidly discover and exploit vulnerabilities – remains a persistent challenge.

Google’s Threat Intelligence Group (GTIG) has observed a significant escalation in the use of Artificial Intelligence (AI) by cybercriminals and nation-state actors, dramatically expanding their attack capabilities and reach. The trend is driven by AI’s ability to automate tasks, accelerate attack timelines, and create sophisticated malware.

TeamPCP (UNC6780), a threat actor linked to China, exemplifies this trend. In less than six hours, the group leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign. Since March 2026, TeamPCP has conducted similar compromises against targets including PyPI, npm, and Docker Hub, and has implemented multiple methods to exploit AI tools and open-source software development practices, including tools like Shai-Hulud and Miasma – which GTIG believes will encourage other actors to emulate these tactics.

Beyond TeamPCP, several nation-state actors are increasingly integrating AI into their operations. UNC6508, a People’s Republic of China (PRC)-nexus threat actor, has been conducting a multi-year cyberespionage campaign targeting academic, medical, and military research institutions in North America. PRC-nexus Basin Castle queries Large Language Models (LLMs) to profile high-value targets, draft and translate localized social engineering lures, author obfuscated custom malware, and troubleshoot post-exploitation commands. Calanque Ion (aka APT42), an Iran-backed group, has used gen-AI (including Gemini) to identify target email addresses, conduct OSINT research, and translate content across local languages to craft localized pretext lures. Ravine Castle (aka APT24), also PRC-nexus, uses Gemini across the entire attack lifecycle from intelligence gathering to attack capability development, and influence operations. It has also been seen using Gemini to generate politically charged propaganda; research methods on anonymizing data leaks for downstream dissemination to journalists and social media influencers.

Google’s response is focused on proactively mitigating these AI-assisted attacks. The company is disrupting adversarial operations by disabling associated projects and accounts whenever it identifies them and hardening its own models against misuse, such as deploying real-time defenses to degrade unauthorized ‘student’ model performance and detect attempts to clone proprietary logic. The core issue remains AI’s inherent ability to rapidly discover and exploit vulnerabilities – a challenge that will likely persist as new software is released.

Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours Related: Google DeepMind Unveils Framework to Exploit AI’s Cyber Weaknesses Related: Cyber Insights 2026: Cyberwar and Rising Nation State Threats

Read the full article at SecurityWeek