{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-prompting-to-autonomy-2026/",
 "asOf": "2026-09-26",
 "id": "gtig-ai-threat-tracker-prompting-to-autonomy-2026",
 "date": "2026-09-08",
 "datePrecision": "day",
 "title": "Google reports attackers moving from prompting to agentic workflows, including a six-hour automated campaign",
 "lane": "attack",
 "kind": "misuse-report",
 "summary": "Google Threat Intelligence Group's September 2026 tracker, drawing on Mandiant incident response, reports adversaries shifting from basic prompting to agentic workflows. In one case a suspected financially motivated actor used an AI coding chatbot and agent instruction files on compromised cloud infrastructure to build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. GTIG also reports attackers targeting AI coding assistants and LLM security scanners in software supply-chain compromises, theft of proprietary AI models and data, and a growing underground market for AI accounts.",
 "whyItMatters": "It documents agentic automation in criminal operations from incident response, not only from a model provider's own platform logs.",
 "actors": [
  "google-threat-intelligence-group",
  "mandiant"
 ],
 "topics": [
  "ai-enabled-intrusion",
  "threat-intelligence",
  "agent-supply-chain",
  "data-exfiltration"
 ],
 "atlas": [],
 "artifacts": [
  "gemini"
 ],
 "sources": [
  {
   "url": "https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai/",
   "publisher": "Google Threat Intelligence Group",
   "title": "GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI",
   "date": "2026-09-08",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "GTIG says the agent instructions let the AI manage the scanning pipeline, troubleshoot and rotate IP addresses without manual intervention; it also says it has not yet seen fully autonomous pipelines deployed against targets in the wild.",
   "locator": "Shift toward agentic AI"
  },
  {
   "fact": "GTIG reports that UNC6780 (TeamPCP) has run open-source supply-chain compromises across PyPI, npm and Docker Hub since March 2026.",
   "locator": "AI-assisted coding pipelines increase open source supply chain risk"
  },
  {
   "fact": "Underground buyer demand concentrated on Claude and Gemini credentials, with average account prices more than doubling in 2026, according to GTIG.",
   "locator": "Illicit account procurement"
  },
  {
   "fact": "GTIG reports PRC-nexus BASIN CASTLE using Gemini for reconnaissance, lures and obfuscated malware, and Iran’s CALANQUE ION (previously tracked as APT42) for reconnaissance, lures and infrastructure.",
   "locator": "Multi-stage lifecycle augmentation"
  }
 ],
 "significance": 5,
 "fideQuestions": [],
 "methods": [
  "agent-orchestrated-intrusion"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}