Google documents autonomous AI campaign that stole thousands of credentials

Google Threat Intelligence Group (GTIG) has described a financially motivated threat actor that used an autonomous, multi-agent attack framework to compromise thousands of third-party credentials in less than six hours. After compromising an unnamed organisation's cloud infrastructure, the actor used an AI coding chatbot, a prompt and agent instructions to plan, build and execute a credential-harvesting operation at scale.
Google said preconfigured Markdown instruction sets acted as operational playbooks. The system carried out automated scanning and credential harvesting, managed the vulnerability-scanning pipeline, troubleshot problems in real time and applied IP-rotation logic without human handholding.
AI assets and developer environments are becoming targets
GTIG said it has observed actors with differing motives targeting proprietary AI models in healthcare, government and media. The activity includes stealing API credentials and using compromised cloud environments to sustain unauthorised AI workloads, reflecting interest in enterprise AI assets for espionage, extortion and resource theft.
John Hultquist, chief analyst at GTIG, said threat actors are using AI in some capacity and benefiting from it. He warned that agentic use can create a faster, more scalable adversary, particularly when criminals select attacks that can be completed faster than defenders can respond.
Google also linked the changing risk to AI-assisted coding tools. Faster development cycles have increased adversary interest in developers, AI coding assistants and LLM security-scanning tools, while raising open-source supply-chain risk.
Supply-chain malware evolves toward AI workspace theft
GTIG identified TeamPCP, also tracked as Altered Spider and UNC6780, as a financially motivated actor behind large-scale software supply-chain compromises involving PyPI, npm and Docker Hub. Following initial compromise, its operations deploy credential stealers to obtain sensitive data and target AI coding assistants, with the results monetised through sale or partnerships with ransomware and data-theft extortion groups.
SANDCLOCK, used in March and April 2026, was primarily written in Python and designed to run on Linux and interact with Kubernetes. Google said it included container-escape capability and targeted cryptocurrency wallets as well as cloud and developer credentials.
Its successor, DUSTMAKER, has been used from April onward. The cross-platform JavaScript payload is optimised for CI/CD pipelines and focuses on credential theft supporting extortion operations. Unlike SANDCLOCK, DUSTMAKER uses AI-focused techniques including poisoning AI assistant workspaces and prompt injection for defence evasion.
Open models change defender visibility
Google also observed theft of proprietary AI data, including models, skills, prompts, source code and research, as well as attempts to distil Google AI models. In one case, China-nexus actor UNC6508 was suspected of compromising cloud environments to deploy local LLM infrastructure using an open-weight model rather than a commercial frontier model, reducing monitoring by model providers.
GTIG noted that API-gated frontier models can give providers visibility into misuse, while local open-model deployments lack centralised defender visibility. The group added that open models also support legitimate innovation and said Google has formalised its Frontier Safety Framework and Critical Capability Levels to assess model capabilities and open-deployment risks.
The practical implication for businesses is to treat cloud credentials, CI/CD systems, developer tooling and AI workspaces as connected security controls, and to ensure monitoring and incident-response processes account for automated scanning, credential theft and rapid operational changes.

