Google Warns AI Gives Lesser Attackers Nation-State
Google's Threat Intelligence Group reports that both criminal and state-backed hackers are using AI to automate attacks, enabling smaller groups to operate

Adversaries are increasingly using artificial intelligence to automate and scale their attacks, according to Google's Threat Intelligence Group. This trend is giving lesser-resourced attackers capabilities once reserved for well-funded nation-state groups.
Google has chronicled this evolution through 2026, noting that what began as simple prompt injections into enterprise AI systems has escalated into a full-blown conflict. Attackers are now developing their own AI systems, while defenders deploy AI-based security tools, creating an expanding loop of attack and defense.
AI Accelerates Attack Timelines
The primary effect of this automation is a dramatic increase in attack speed. The group tracked as TeamPCP, or UNC6780, provides a stark example. Google researchers state that this threat actor used an AI coding chatbot, a prompt, and agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.
This capability allows attackers to operate at a scale typically associated with larger, better-resourced groups. TeamPCP has also been active in exploiting the open-source software supply chain since March 2026, targeting repositories including PyPI, npm, and Docker Hub.
Nation-State Actors Embrace AI Tools
Financially motivated criminals are not the only ones use AI; nation-state actors are also deeply invested. Google's GTIG reported in June 2026 on a multi-year cyberespionage campaign by UNC6508, a People's Republic of China-nexus threat actor, targeting academic, medical, and military research institutions in North America.
Various state-linked groups are developing offensive, agentic AI tools. One PRC group has been experimenting with AI-powered development tools to build an automated exploitation and post-exploitation pipeline. Another, known as Basin Castle, has been seen querying large language models to profile high-value targets, draft localized social engineering lures, author obfuscated malware, and troubleshoot commands.
| Actor Group | Alleged Nexus | AI Use Case |
|---|---|---|
| Basin Castle | PRC | Target profiling, lure drafting, malware authoring |
| Calanque Ion (APT42) | Iran | OSINT research, email identification, content translation |
| Ravine Castle (APT24) | PRC | Full attack lifecycle, propaganda generation |
| Midnight Neptune (UNC1069) | DPRK | Supporting cryptocurrency theft operations |
Iran-backed Calanque Ion, also known as APT42, has used generative AI, including Google's Gemini, to identify target email addresses, conduct open-source intelligence research, and translate content to craft localized lures. PRC-nexus Ravine Castle uses Gemini across the entire attack lifecycle, from intelligence gathering to developing attack capabilities and running influence operations. The group has also used the AI to generate politically charged propaganda and research methods for anonymizing data leaks.
Google's Defensive Response
In response to the surge in AI-assisted attacks, Google disrupts adversarial operations by disabling associated projects and accounts when identified. The company also hardens its own AI models against misuse. "In response to model extraction, or 'distillation', attacks, we have deployed real-time defenses designed to degrade the performance of unauthorized 'student' models and detect attempts to clone proprietary logic," the company stated.
The core challenge is AI's inherent ability to find vulnerabilities and develop new malware and exploits. As long as this persists, malicious actors will use AI as a force multiplier. Vulnerabilities will continue to emerge in new software as fast as old ones are patched. While defenders like Google may find and disrupt adversarial activities, the attackers will adapt and persist, a pattern constant in cybersecurity that AI is now accelerating with greater speed and scale.





