cd /news/ai-safety/threat-actors-are-coming-for-your-ai… · home topics ai-safety article
[ARTICLE · art-130005] src=csoonline.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Threat actors are coming for your AI assets to operationalize their use of AI

Google Threat Intelligence Group (GTIG) reported that state-affiliated cyberespionage groups and cybercrime gangs are targeting enterprise AI assets — including proprietary models, model weights, source code, API credentials, and cloud compute quotas — for espionage, extortion, and resource theft. GTIG observed model distillation campaigns involving more than 100 million prompts against Google's own audio, video, and image generation models, launched through proxy networks using thousands of compromised account credentials, and Mandiant investigated second-quarter 2026 breaches in which attackers stole a proprietary AI model from a healthcare organization and source code, prompts, skills, model scripts, and secrets from an AI media generation company. The NSA, FBI, and CISA separately published an advisory accusing China-based AI labs of industrial-scale distillation against US frontier AI models.

read4 min views1 publishedSep 15, 2026

Both state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of LLMs is being extracted with targeted prompts, is increasing.

“GTIG observed adversaries with wide-ranging motivations target proprietary AI models and source code, exfiltrate application programming interface (API) credentials, and co-opt victim cloud environments to sustain unauthorized AI workloads,” the Google Threat Intelligence Group (GTIG), said in their latest quarterly AI Threat Tracker report released last week. “This shift underscores that enterprise AI assets — from model weights to cloud compute quotas — are high-value targets for espionage, extortion, and resource theft.”

This threat activity didn’t affect just AI labs, but also government, military, healthcare, and media organization that might train or fine-tune their own models. Even if they don’t do any AI model development themselves, organizations might have a lot of valuable AI-related proprietary data on their systems, from RAG pipelines to custom workflows, agents, and credentials.

Back in June, GTIG warned about a China-based cyberespionage group tracked as UNC6508 that targeted organizations involved in academic, healthcare, and defense research. The information collected by this group included AI research.

UNC6508 was also seen compromising cloud environments to deploy LLM infrastructure for its own use, researching how to deploy LLMs locally and investigating vulnerabilities in AI models.

During the second quarter of 2026, Google’s Mandiant incident response arm investigated breaches by data extortion groups that involved theft of AI models, skills, prompts, source code, and related research.

In one case, a threat actor breached a healthcare organization and stole drug research and other corporate data, including a proprietary AI model. In a separate incident, attackers compromised an AI media generation company and stole proprietary source code, prompts, skills, model scripts, and secrets.

GTIG also warns in its report about an increase in model distillation attack campaigns against Google’s own AI models. These attacks attempt to extract model outputs for targeted prompts to train other models on those outputs. Google observed campaigns involving more than 100 million prompts targeting audio, video, and image generation capabilities. These campaigns are launched through proxy networks using thousands of compromised account credentials.

The US National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory last week accusing China-based AI labs of engaging in industrial-scale distillation against US frontier AI models.

“Businesses not directly associated with frontier AI models may be tempted to disregard these campaigns as irrelevant due to them being a national security issue, but the exposure of model access to customers or partners makes API keys and service accounts valuable targets, with abuse of access to those models appearing as legitimate,” Ismael Valenzuela, VP of labs, threat research, and intelligence at Arctic Wolf, tells CSO.

In addition to using stolen AI-related credentials for distillation campaigns, hackers also need them for automating other offensive operations that include a high level of automation via AI agents.

Mandiant observed a financially motivated threat actor use compromised cloud infrastructure credentials to deploy an autonomous multi-agent attack framework. The resources enabled the attacker to plan, build, and execute a mass credentials harvesting campaign in less than 6 hours.

“Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials,” the researchers said. “The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute Internet Protocol (IP) rotation logic without manual intervention — significantly reducing the human-in-the-loop latency.”

The GTIG researchers also uncovered an automated reconnaissance and credential management framework called Recon that was being used on a live command-and-control server to manage more than 23,000 stolen credentials, including API keys for cloud infrastructure and AI services.

A Chinese threat actor known for targeting government organizations was also observed building an AI-powered exploitation and post-exploitation pipeline, automating the entire attack chain from reconnaissance to credential scraping for lateral movement.

“GTIG continues to observe the widespread adoption and incorporation of AI technologies by threat actors with wide-ranging motivations across multiple geographic portfolios,” the researchers said. “Threat actors continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration. Key examples from the last quarter include PRC- and Russia-nexus espionage groups; financially-motivated and espionage-related activity attributed to the Democratic People’s Republic of Korea (DPRK); financially-motivated cyber crime groups; and state-sponsored IO [influence operations] groups.”

Some examples of such groups include:

“In order to experiment with generative AI tools, threat actors must obtain and maintain access to those tools,” the researchers explain. “The cost of premium model access and high-performance compute is one of the primary barriers for threat actors seeking to operationalize AI. This has resulted in increased targeting, exfiltration, and sale of AI accounts across cyber crime communities coupled with a growing number of intrusions involving the compromise of enterprise cloud environments to hijack compute resources (aka ‘LLMJacking’).”

── more in #ai-safety 4 stories · sorted by recency
── more on @google threat intelligence group 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/threat-actors-are-co…] indexed:0 read:4min 2026-09-15 ·