AI gives small attackers nation-state-level reach
Google’s Threat Intelligence Group warned AI lets small attackers automate and scale attacks, reporting TeamPCP used an AI coding chatbot to mount a mass credential-theft campaign in under six hours.
Google’s Threat Intelligence Group reported attackers are using AI to automate and scale cyberattacks. GTIG documented TeamPCP, tracked as UNC6780, using an AI coding chatbot together with prompts and agent instructions to plan, build and execute a mass credential-harvesting campaign in less than six hours.
GTIG warned the group’s public releases and apparent operational success could prompt other actors to copy the tactics. Since March 2026 TeamPCP targeted open-source repositories and registries including PyPI, npm and Docker Hub, embedded exploitation methods in malware such as the Dustmaker credential stealer, and publicly released tools named Shai-Hulud and Miasma.
GTIG reported the actor implemented more than six distinct methods to attack or exploit AI tools and open-source development practices, creating multiple vulnerabilities for defenders to track.
The group described similar AI use by actors linked to nation states. A multi-year campaign by UNC6508, described as PRC-linked, targeted academic, medical and military research institutions in North America. Basin Castle used large language models to profile high-value targets, draft and translate localized social-engineering lures, produce obfuscated malware and troubleshoot post-exploitation commands. Calanque Ion, known as APT42 and tied to Iran, used generative AI to identify target email addresses, gather open-source intelligence and translate material for tailored lures. Ravine Castle, tracked as APT24 and linked to the PRC, applied a commercial model across intelligence gathering, attack development and influence operations, including generating propaganda and researching ways to anonymize leaked data. Midnight Neptune, tracked as UNC1069 and tied to the DPRK, used AI in operations that support cryptocurrency theft.
Google’s response focuses on disrupting identified adversary activity and strengthening model defenses. The company disables projects and accounts tied to malicious campaigns when they are identified. To counter model-extraction attacks, Google deployed real-time defenses designed to degrade unauthorized “student” models and detect attempts to clone proprietary logic. Google reported upgrades to protections intended to prevent model misuse.
GTIG pointed to technical drivers behind the activity: automation speeds development of malware and exploits, and AI can find vulnerabilities faster than human attackers working alone. The group noted enterprises’ use of defensive AI can create new vectors for manipulation as software and infrastructure change. GTIG framed the situation as an acceleration of existing trends in cybercrime and espionage, saying automation and public releases increase the reach of smaller groups and narrow the gap between under-resourced actors and those with state backing.








