Google Threat Intelligence Group (GTIG) released research findings regarding the misuse of AI in September 2026. According to the report, the use of AI by attackers is shifting from a stage of task assistance using generative AI to a stage where multiple AI agents are combined to autonomously advance attack processes.
Attackers Exploit AI Agents as Autonomous Attack Infrastructure, Google Releases Findings
This article is a translation. Read the Japanese original
In a case from the 4th quarter of 2026 2, an attacker executed a large-scale credential harvesting campaign using AI within just six hours after compromising a company's cloud environment. The attacker provided the agent with pre-prepared instructions and knowledge files, forcing it to perform a continuous series of tasks such as vulnerability scanning, analysis, and troubleshooting.
Additionally, movements toward supply chain attacks targeting AI coding environments have been confirmed. The threat actor "UNC6780" has embedded malicious code into MCP (Model Context Protocol) related tools and utilized malware named "DUSTMAKER," which places malicious files in hidden directories of IDEs (Integrated Development Environments) used by developers.
Furthermore, an attack known as "LLMJacking" has been identified, where a local LLM is deployed within a compromised cloud environment to use the victim company's computing resources for AI workloads without authorization. GTIG points out that attackers are beginning to use AI not merely as a task assistance tool, but as an autonomous mechanism to sustain attacks.
Sources
- 「AIを盗む」のではなく「AIを動かす」ために Googleが捉えた攻撃者の異変 (ITmedia AI+、2026-09-15)