Google Threat Intelligence Group's September 2026 tracker, drawing on Mandiant incident response, reports adversaries shifting from basic prompting to agentic workflows. In one case a suspected financially motivated actor used an AI coding chatbot and agent instruction files on compromised cloud infrastructure to build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. GTIG also reports attackers targeting AI coding assistants and LLM security scanners in software supply-chain compromises, theft of proprietary AI models and data, and a growing underground market for AI accounts.
It documents agentic automation in criminal operations from incident response, not only from a model provider's own platform logs.
Key facts
As stated in the sources, with where to find them.
- GTIG says the agent instructions let the AI manage the scanning pipeline, troubleshoot and rotate IP addresses without manual intervention; it also says it has not yet seen fully autonomous pipelines deployed against targets in the wild.Shift toward agentic AI
- GTIG reports that UNC6780 (TeamPCP) has run open-source supply-chain compromises across PyPI, npm and Docker Hub since March 2026.AI-assisted coding pipelines increase open source supply chain risk
- Underground buyer demand concentrated on Claude and Gemini credentials, with average account prices more than doubling in 2026, according to GTIG.Illicit account procurement
- GTIG reports PRC-nexus BASIN CASTLE using Gemini for reconnaissance, lures and obfuscated malware, and Iran’s CALANQUE ION (previously tracked as APT42) for reconnaissance, lures and infrastructure.Multi-stage lifecycle augmentation
Findings that cite this record
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.