← All posts / Meta

Six Hours, Thousands of Credentials: Google's GTIG Documents the Shift From Prompting to Agentic Attacks

Google's latest AI Threat Tracker chronicles an autonomous multi-agent credential harvest that compromised thousands of logins in under six hours — and a broad pivot by adversaries toward AI assets and agent-driven operations.

Six Hours, Thousands of Credentials: Google's GTIG Documents the Shift From Prompting to Agentic Attacks

In Q2 2026, a financially motivated threat actor compromised a cloud environment, opened an AI coding chatbot, fed it a prompt and a set of agent instructions, and walked away. By the time defenders typically finish their first triage call, the machine had planned, built, and executed a mass credential harvesting campaign — thousands of third-party credentials compromised in less than six hours.

That incident is the centerpiece of the latest edition of Google Threat Intelligence Group’s AI Threat Tracker, published September 8 under the title “From Prompting to Autonomy – The Evolution of Adversarial AI.” The report’s thesis is captured in its own name: adversaries have moved past using large language models as writing assistants for phishing lures. They are now delegating operational phases of attacks — scanning, troubleshooting, infrastructure management — to AI agents that run at machine speed.

Anatomy of a six-hour campaign

The details Google discloses are sparse but striking. After compromising an unnamed organization’s cloud infrastructure, the attacker deployed an autonomous, multi-agent attack framework. The setup consisted of little more than an AI coding chatbot, an initial prompt, and preconfigured Markdown instruction sets that functioned as operational playbooks.

From there, the system ran itself. The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting when things broke, and execute IP rotation logic — all without manual intervention. Operating from the victim’s own cloud infrastructure had an additional benefit: attack traffic originated from legitimate IP addresses, defeating the reputational blocklists that normally degrade mass-scanning campaigns.

The result, per Google, was an operation at “a scale and velocity typically associated with larger and more resource-heavy groups.” A single actor, in one working afternoon, achieved what used to require a team.

Two important caveats keep this in perspective. Google explicitly notes it has not observed fully autonomous zero-day campaigns — a human still planned the operation and set the objectives. And the target set appears to have been vulnerable, exposed services rather than novel exploitation. This was orchestration at machine speed, not hands-off superintelligence. But the compression of the attack timeline is the story: when scanning, error correction, and evasion rotate faster than human responders can react, the traditional defense window collapses.

The supply chain front: TeamPCP, SANDCLOCK, and DUSTMAKER

The agentic campaign sits inside a broader deterioration of the software supply chain. GTIG attributes a series of large-scale compromises of PyPI, npm, and Docker Hub to a financially motivated actor it tracks as TeamPCP (also known as Altered Spider and UNC6780), whose campaigns deliberately trick AI coding assistants and LLM-based security scanners into propagating malicious packages.

The group’s tooling has evolved in ways that directly target the AI development stack. SANDCLOCK, used in March and April 2026, was a Python-based credential stealer designed for Linux and Kubernetes, with container escape functionality that targeted cryptocurrency wallets alongside cloud and developer credentials. Its successor DUSTMAKER, in use from April onward, is a cross-platform JavaScript payload optimized for CI/CD pipelines — and it added techniques exclusive to the AI era: poisoning AI assistant workspaces and using prompt injection for defense evasion.

Stolen access is then monetized directly or through partnerships with ransomware and data-theft extortion groups, closing the loop between supply chain compromise and enterprise extortion.

AI assets are now the target, not just the weapon

A third trend may matter most for enterprises building with AI: the models themselves have become loot. GTIG observed adversaries with motivations spanning espionage, extortion, and resource theft targeting proprietary AI models, source code, prompts, and research — particularly in healthcare, government, and media.

One China-nexus cluster, tracked as UNC6508, compromised cloud environments specifically to deploy local LLM infrastructure running open-weight models. Because the models run locally on stolen compute, no commercial AI provider sees the traffic — surveillance by model providers simply doesn’t reach it. Other groups have been caught running distillation attacks against Google’s visual, audio, image generation, and video generation capabilities, effectively stealing model behavior to bootstrap their own.

State actors remain deeply embedded in this ecosystem. A China-aligned espionage group used Gemini to design an automated penetration testing framework — an agentic architecture intended to observe target state, reason through actions, and execute tasks in unpredictable environments. Sandworm used Gemini for intelligence gathering and workflow automation against Ukraine. Iran’s Calanque Ion (APT42) used generative AI for reconnaissance and social engineering. ShinyHunters used Claude Code to bypass Cloudflare guardrails and analyze exfiltrated data for extortion. The through-line is that LLM access has become a standard line item in adversary toolkits across every major geopolitical actor.

The open-weight dilemma

The report’s most consequential policy argument concerns open-weight models. GTIG warns that “abliterated” — safety-stripped — variants of open models give threat actors capable local deployment with no provider visibility, accelerating phishing and malicious scripting. Yet the same report acknowledges that gating access is impractical because open models drive essential innovation.

Google’s proposed middle path is its Frontier Safety Framework and Critical Capability Levels, which attempt to evaluate when a model’s open deployment poses unacceptable security risk — a notably self-interested framework given Google’s commercial stake in API-gated deployment, but a serious attempt at the problem regardless. GTIG calls for enforceable, industry-wide safety baselines for open-source AI and coordinated platform policies to restrict uncensored checkpoints.

What defenders should take from this

The operational implications are concrete. First, exposure management timelines need to shrink: a vulnerability that would have been found “eventually” is now found in hours by autonomous scanners rotating through clean IPs. Second, AI development infrastructure — coding assistants, model registries, CI/CD pipelines, agent workspaces — is now a primary attack surface, and prompt injection is a defense-evasion technique, not a chatbot curiosity. Third, cloud credential hygiene and egress monitoring matter more when the attacker’s compute is your compute.

“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited,” GTIG chief analyst John Hultquist told The Hacker News. The six-hour campaign shows what that means in practice: not a superintelligent adversary, but a fast, tireless, self-correcting one. For defenders still operating on human reaction times, that distinction is proving expensive.