State-Backed Hackers Now Use AI to Automate Cyberattacks
Google's threat intelligence team documents Russian, Chinese, Iranian and North Korean groups integrating large language models into espionage and credential theft operations.
State-sponsored hacking groups have moved beyond experimenting with artificial intelligence to embedding it directly into their attack infrastructure, according to Google's latest threat intelligence findings.
The Google Threat Intelligence Group documented multiple nation-state actors using large language models to automate reconnaissance, write malicious code, and execute attacks that previously required significantly more time and resources. The shift marks what Google's Chief Analyst John Hultquist calls a fundamental change in the economics and speed of cybercrime.
"At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," Hultquist said in the Q3 2026 AI Threat Tracker report.
Russian groups automate intelligence gathering
Russian threat actor UNC5792 has integrated AI models into automated monitoring systems that scan Telegram channels for information relevant to Russian authorities. The group uses AI to analyze messages, flag suspicious activity, and generate structured intelligence reports without manual review.
Another Russian espionage group, SANDWORM RELIC—also tracked as FROZENBARENTS and APT44—incorporated Google's Gemini model into operations targeting Ukraine. The group used Gemini to write Python scripts for password spraying and endpoint fingerprinting, while exploring ways to interface directly with the Gemini API for workflow automation.
Chinese actors build autonomous attack frameworks
A Chinese cyber espionage group known as BASIN CASTLE has embedded large language models throughout its attack cycle, from initial target research to troubleshooting errors during active intrusions. Another China-linked group attempted to build an automated penetration testing framework using Gemini that could autonomously execute early intrusion stages before Google disabled the associated assets.
Mandiant researchers observed one threat actor deploy an autonomous, multi-agent attack framework that compromised thousands of credentials within six hours—a speed and scale typically associated with much larger operations.
Iranian influence operations generate synthetic personas
Iranian state-aligned actors are using Gemini to create photorealistic fake personas for influence campaigns, crafting detailed prompts that specify camera angles, lighting, and facial textures. Other Iranian groups instructed language models to adopt personas including psychological operations experts to develop counter-influence narratives.
AI supply chain emerges as new target
Threat actors are also targeting the infrastructure that supports AI systems. TeamPCP, tracked as UNC6780, conducted multiple software supply chain compromises in 2026 across PyPI, npm, and Docker Hub. The group backdoored Model Context Protocol tools used by AI coding assistants and poisoned open-source package metadata to trick AI systems into recommending malicious dependencies to developers.
A China-linked group designated UNC6508 used compromised cloud environments to host local AI models, allowing the attackers to avoid commercial API monitoring while stealing compute resources from victims. North Korean IT workers registered large numbers of language model API accounts using hijacked credentials.
Why it matters
The integration of AI into state-sponsored hacking operations represents a capability leap that compresses attack timelines from days to hours. Organizations now face adversaries that can automate reconnaissance, code generation, and credential theft at machine speed—while simultaneously becoming targets themselves as AI infrastructure enters corporate technology stacks. The emergence of AI supply chain attacks creates new exposure for any organization adopting AI development tools.
The findings were first reported by Google Threat Intelligence Group in its Q3 2026 AI Threat Tracker.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call