securityonline.info 14 Sept 2026, 01:01 UTC

Google Says AI Is Accelerating Supply Chain and Cloud Attacks

Google Says AI Is Accelerating Supply Chain and Cloud Attacks
CyberSIXT Evidence Panel
Threat Actor
UNC6780

GOOGLE Threat Intelligence Group (GTIG) says suspected state-sponsored groups and cybercriminals are using artificial intelligence to accelerate software supply-chain attacks, credential theft and cloud-resource hijacking. The activity reportedly targets healthcare, government and media organisations, as well as software developers, with attackers seeking proprietary models, source code and API keys.

GTIG said one cloud resource was compromised and then used to plan, build and execute an agent-enabled mass credential-harvesting campaign in under six hours.

The report names financially motivated UNC6780, which allegedly compromised legitimate developer accounts to inject malicious code into repository environments, and suspected China-nexus group BASIN CASTLE, which used generative tools to profile targets and translate localised phishing lures. A suspected Russia-based group, UNC5792, reportedly automated analysis of Telegram channels and obtained developer credentials by stealing them or buying compromised platform accounts.

GTIG also observed an autonomous framework called “Recon” organising and validating more than 23,800 harvested secrets, including cloud-service API keys. Other campaigns reportedly exceeded 100 million model-distillation prompts, although the article does not establish specific victims or financial losses.

The recommended response includes monitoring continuous-integration pipelines for unusual activity, restricting outbound connections from build environments, auditing cloud quotas for hijacking and applying strict access controls. Organisations are also advised to monitor API usage for anomalies. The article attributes the findings to GTIG and describes the groups as suspected; it does not report official charges or confirm exploitation of particular named victims.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline