Google Warns of AI Agents Used by Cyber Attackers, Iran
Google's Threat Intelligence Group (GTIG) has released its Q2 2026 report, revealing a significant shift by malicious actors and nations towards employing autonomous AI agents. This advancement dramatically shortens attack timelines, outpacing traditional cyber defenses. The report highlights Iran's expanding use of AI, including models like Gemini, for developing attack infrastructure and conducting influence operations. Alongside Iranian activity, the report details sophisticated campaigns originating from China and financially motivated attacks executed within hours.
Iranian state-sponsored groups, such as APT42, are leveraging large language models for intelligence gathering, rapid translation of phishing content, and developing tactical attack infrastructure. They are also reportedly reverse-engineering software licensing algorithms to bypass enterprise defenses. Iran's influence operations have also been upgraded, with AI models generating detailed prompts for image generators to create photorealistic fake personas and crafting psychologically manipulative messages to serve the regime's interests.
The report specifically notes the emergence of 'Agentic AI,' autonomous agents capable of independent decision-making and real-time problem-solving. In one instance, a financially motivated attacker used a chatbot and a simple prompt to plan, build, and execute a vulnerability scanning and password theft campaign in under six hours. The AI agent autonomously handled technical issues and rotated IP addresses to evade detection.
Further findings include a financial cybercrime group, UNC6780 (TeamPCP), embedding extreme prompts within malicious code to trick security scanners into bypassing analysis, thereby allowing malware to run undetected. Chinese cyber-espionage group UNC6508 is also detailed, targeting North American academic, medical, and military research institutions to steal proprietary AI research and establish local models within compromised cloud environments, exploiting victim resources and evading commercial API monitoring.
Google has stated that all identified malicious activities using its AI models have been blocked, with associated accounts and projects permanently suspended. The company is using insights from these attack attempts to enhance its safety filters and models. John Dwyer, lead analyst at GTIG, commented that "all adversarial actors are using AI to some extent" and that their capabilities have "significantly improved." He expressed concern over the increasing autonomy and speed of AI-driven attacks, predicting a future where adversaries operate at a much larger scale and faster pace.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.