Adversaries Leverage AI to Scale Attacks at Nation-State Level
Google's Threat Intelligence Group has warned that adversaries, including both financially motivated criminals and nation-state actors, are increasingly using AI to automate and scale their attacks. This trend is exemplified by TeamPCP (UNC6780), a threat actor that leveraged an AI coding chatbot to plan, build, and execute a mass credential harvesting campaign in less than six hours.
TeamPCP has also been involved in compromising open-source supply chain targets, including PyPI, npm, and Docker Hub. Its Dustmaker credential stealer software features multiple methods to target or exploit AI tools and open-source software development practices.
Nation-state actors are not the only ones taking advantage of AI's capabilities for malicious purposes. Google itself has been seen experimenting with Gemini, an AI tool that can be used both defensively and offensively.