Google Warns of AI Agents Used by Cyber Attackers, Iran
Google's Threat Intelligence Group (GTIG) has released its Q2 2026 report, revealing a significant shift by malicious actors and nations towards employing autonomous AI agents. This advancement dramatically shortens attack timelines, outpacing traditional cyber defenses. The report highlights Iran's expanding use of AI, including models like Gemini, for developing attack infrastructure and conducting influence operations. Alongside Iranian activity, the report details sophisticated campaigns originating from China and financially motivated attacks executed within hours.
Iranian state-sponsored groups, such as CALANQUE ION (APT42), are leveraging large language models for intelligence gathering, rapid translation of phishing content, and developing tactical attack infrastructure. They are also reportedly reverse-engineering software licensing algorithms to bypass enterprise defenses. Iran's influence operations have also been upgraded, with AI models generating detailed prompts for image generators to create photorealistic fake personas and crafting messages using psychological manipulation techniques to serve the regime's interests.
The report specifically notes the rise of "Agentic AI," autonomous agents capable of independent decision-making and real-time problem-solving. In one instance, a financially motivated attacker used a chatbot and a simple prompt to plan, build, and execute a vulnerability scanning and password theft campaign in under six hours. The AI agent autonomously handled technical issues and rotated IP addresses to evade detection.
Further findings include the financial cyber group UNC6780 (TeamPCP) embedding extreme prompts, such as requests for biological or nuclear weapon development, within malicious code. This tactic aims to trigger safety mechanisms in AI-based security scanners, causing them to refuse analysis and allowing the underlying malware to evade detection.
Chinese cyber-espionage group UNC6508 is also identified for its prolonged campaign targeting academic, medical, and military research institutions in North America. Their focus is on stealing proprietary AI research by breaching cloud environments and establishing local models with "open weights" to exploit the victim's computing resources and evade commercial API monitoring.
Google stated that all identified malicious activities using its AI models triggered safety mechanisms, leading to the permanent blocking of associated accounts and projects. The company is using insights from these attack attempts to strengthen its safety filters and models. John Hultquist, Chief Analyst at Google Threat Intelligence, commented that "all adversarial actors are using AI to some extent," and their capabilities have significantly improved, posing a growing challenge as AI becomes more integrated into autonomous attack operations.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.