Chronicle/Attacks & incidents

Google reports attackers moving from prompting to agentic workflows, including a six-hour automated campaign

AttackMisuse reportSignificance assistant-drafted

Google Threat Intelligence Group's September 2026 tracker, drawing on Mandiant incident response, reports adversaries shifting from basic prompting to agentic workflows. In one case a suspected financially motivated actor used an AI coding chatbot and agent instruction files on compromised cloud infrastructure to build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. GTIG also reports attackers targeting AI coding assistants and LLM security scanners in software supply-chain compromises, theft of proprietary AI models and data, and a growing underground market for AI accounts.

Why it matters

It documents agentic automation in criminal operations from incident response, not only from a model provider's own platform logs.

Key facts

As stated in the sources, with where to find them.

  • GTIG says the agent instructions let the AI manage the scanning pipeline, troubleshoot and rotate IP addresses without manual intervention; it also says it has not yet seen fully autonomous pipelines deployed against targets in the wild.Shift toward agentic AI
  • GTIG reports that UNC6780 (TeamPCP) has run open-source supply-chain compromises across PyPI, npm and Docker Hub since March 2026.AI-assisted coding pipelines increase open source supply chain risk
  • Underground buyer demand concentrated on Claude and Gemini credentials, with average account prices more than doubling in 2026, according to GTIG.Illicit account procurement
  • GTIG reports PRC-nexus BASIN CASTLE using Gemini for reconnaissance, lures and obfuscated malware, and Iran’s CALANQUE ION (previously tracked as APT42) for reconnaissance, lures and infrastructure.Multi-stage lifecycle augmentation

Findings that cite this record

Key questions this bears on

Sources

Related records