Google Threat Intelligence Group (GTIG) says cyber threat actors are moving beyond one-off prompts and coding assistance toward agentic artificial intelligence systems that can coordinate multiple stages of an attack with limited human involvement.
The assessment, published on September 8 in GTIG’s latest AI Threat Tracker, draws on second-quarter 2026 incident-response work and threat monitoring. It includes activity attributed by Google to China- and North Korea-linked groups, as well as financially motivated operators, giving the findings direct relevance to security teams across Asia.
Automation compresses the response window
In the clearest example, Mandiant investigators said an attacker first compromised an organization’s cloud environment and then used it to plan, build and run a multi-agent credential-harvesting campaign in less than six hours. The framework collected thousands of credentials, according to Google.
The agents handled tasks including vulnerability scanning, credential collection, troubleshooting and IP rotation. Because some activity originated from the victim’s own cloud infrastructure, simple controls based on the apparent source of network traffic could be less effective. Independent coverage by BleepingComputer also highlighted the incident and the shortening time available for defenders to detect and contain a compromise.
Google did not identify the victim, disclose the precise models used or say that AI gained the initial access. The sequence is therefore important: the report describes AI accelerating activity after an environment had already been compromised, rather than independently discovering and exploiting an unknown vulnerability.
That distinction affects defensive priorities. Security teams still need conventional controls around initial access, but they may also need alerts for machine-speed activity after a valid cloud identity or workload is compromised. Processes built around a human attacker’s pace could become too slow.
State-linked groups broaden their use of AI
GTIG said a group it tracks as BASIN CASTLE used large language models for activities ranging from target research to troubleshooting during intrusions. Another actor attempted to develop an automated penetration-testing framework, according to the report.
The company also described supply-chain activity by UNC6780, also known as TeamPCP. Google said the group sought to compromise developers through malicious packages, model-context-protocol servers and other resources likely to be surfaced by AI coding tools. Mandiant detected attempted downloads of malicious AI-related resources in North America and Asia, although the report did not identify affected organizations or confirm that every attempt succeeded.
Activity also included bulk registration of application programming interface accounts by suspected information-technology workers and an April incident in which a compromised cloud graphics-processing-unit workload was used for unauthorized computing, GTIG said. These findings remain Google’s attribution assessments rather than independently established facts.
AI systems are also becoming targets
The report says threat actors are increasingly seeking proprietary models, code, prompts, research data, credentials and cloud computing capacity. That widens the security problem beyond the misuse of public chatbots: companies developing or deploying AI may need to treat model artifacts, agent credentials and inference infrastructure as high-value assets.
At the same time, Google said it has not observed a fully autonomous, end-to-end pipeline exploiting previously unknown vulnerabilities in the wild. Most activity reflects gradual operational improvement, such as faster use of known vulnerabilities, automated reconnaissance and more scalable social engineering.
GTIG recommends that organizations monitor agent and cloud identities, look for unusual high-speed task sequences, restrict access to model and development assets, and preserve human review over sensitive actions. Google said it disabled accounts and other assets connected to abuse and used the findings to strengthen safeguards.
For Asia-Pacific organizations, the report points to a narrower reaction window and a broader set of systems to defend. Its most consequential claims, however, depend on Google’s private telemetry and incident-response visibility, so the named attributions and quantitative findings should be treated as the company’s assessment unless corroborated by affected parties or public authorities.
Featured image: Growtika on Unsplash
Philippines’ DICT, Google Cloud expand AI and cybersecurity partnership

