Google Threat Intelligence Group said a suspected financially motivated threat actor used AI to plan, build, and run a mass credential-harvesting campaign in less than six hours during the second quarter of 2026.
The campaign compromised thousands of third-party credentials, with the attackers using AI agents to handle troubleshooting and IP rotation without manual intervention, GTIG said in a report published on Tuesday.
According to the report, threat actors have turned to AI for reconnaissance, malware development, vulnerability research, and post-exploitation, although fully autonomous attacks against live targets have yet to be observed.
GTIG also linked UNC6780, also known as TeamPCP, to large-scale open-source supply-chain attacks targeting PyPI, npm, and Docker Hub. The group used trojanized MCP server forks and malicious GitHub workflows to manipulate AI coding assistant workspaces and extract credentials.
"Following initial compromise, UNC6780 typically deploys credential stealers to obtain proprietary data and credentials, which are subsequently monetized either through the direct sale of the stolen data or through partnerships with ransomware and data theft extortion groups," the group wrote. "The publicity, apparent success, and open-source release of UNC6780's malware will likely spur adversary emulation of these tactics."
Proprietary AI assets have also become a growing target, GTIG said. Mandiant investigated multiple Q2 incidents involving the theft of AI models, source code, prompts and related research from technology, healthcare and media companies.
Since February, GTIG said model-distillation attacks targeting Google AI models have increased in scale and sophistication, with some coordinated campaigns exceeding 100 million prompts.
Google disrupted the campaigns it identified and used the findings to strengthen Gemini's safety systems and other defenses against AI-enabled abuse, according to the report.
