Overview
- Google’s Threat Intelligence Group published its Q3 2026 report on Tuesday and said researchers observed a financially motivated actor plan, build and deploy a mass credential‑harvesting campaign in under six hours using an autonomous multi‑agent AI framework.
- Investigators found a live command‑and‑control system called Recon that organized and validated more than 23,800 harvested secrets, including API keys for cloud and AI services, showing credential theft at industrial scale.
- A China‑linked group tracked as UNC6508 was observed compromising cloud tenants and running open‑weight AI models on victim infrastructure to run workloads without using monitored commercial APIs.
- The financially motivated cluster UNC6780 (aka TeamPCP/Altered Spider) used supply‑chain compromises on PyPI, npm and Docker Hub and deployed Dustmaker credential‑stealers to target AI developer environments and CI/CD pipelines.
- Google says it has disrupted many campaigns by using model detections and account bans, but it warns defenders face rising exposure from open models, compromised cloud hosts, and rapid agent experimentation even though fully autonomous zero‑day pipelines are not yet widespread.