AI Is Handing Budget Hackers Nation-State Firepower, Google Reports
Google's Threat Intelligence Group has published findings that make for uncomfortable reading: AI is compressing the gap between scrappy criminal outfits and well-funded state-sponsored operations. What used to require significant resources and expertise can apparently now be knocked together in an afternoon.
The clearest example is TeamPCP, tracked as UNC6780. According to Google's researchers, this group used an AI coding chatbot, a handful of prompts, and some agent instructions to plan, build, and run a mass credential harvesting campaign in under six hours. That kind of operational tempo used to be the preserve of nation-state teams with deep benches. Not anymore.
TeamPCP has been busy since March 2026, compromising targets across PyPI, npm, and Docker Hub, and deploying more than half a dozen techniques targeting AI tools and open source development pipelines. Some of these are baked into its Dustmaker credential stealer. The group also released two tools publicly: Shai-Hulud and Miasma. Google expects this open-source generosity will encourage copycat behaviour. When something works and gets published, people use it.
Criminals are only part of the picture. Nation-state actors are leaning into AI just as aggressively. In June 2026, Google reported on a multi-year espionage campaign by UNC6508, a China-linked group targeting academic, medical, and military research institutions across North America.
China-linked Basin Castle has been observed using LLMs for early reconnaissance, drafting localised social engineering lures, writing obfuscated malware, and debugging post-exploitation commands. Essentially the full attack workflow, assisted by AI at each stage.
Another China-nexus group, Ravine Castle (also known as APT24), uses Gemini across the entire attack lifecycle, from intelligence gathering through to influence operations. This includes generating politically charged propaganda and researching how to anonymise leaked data before feeding it to journalists and social media.
Iran's APT42, which Google tracks as Calanque Ion, has used generative AI including Gemini to identify target email addresses, conduct open-source intelligence work, and translate materials to craft convincing localised lures.
Then there is Midnight Neptune, a North Korea-linked actor that has woven AI throughout its operations, with a particular focus on cryptocurrency theft.
Google's response involves disabling accounts and projects tied to adversarial activity as they are identified, and hardening its own models against misuse. On the model extraction front, Google says it has deployed real-time defences designed to degrade the performance of unauthorised student models attempting to clone proprietary logic.
None of this will fully solve the problem, and Google is candid enough not to pretend otherwise. AI is good at finding vulnerabilities and generating new malware. Vulnerabilities are not a finite resource. Patch one batch and new software produces fresh ones. The attackers disrupted today will move, adapt, and return tomorrow under different names with updated tools.
Cybersecurity has always operated this way. AI does not change the fundamental dynamic, it just adds speed, scale, and a significantly lower bar to entry. The warzone stays the same. The weapons get cheaper and faster.