Google Report: State Actors and Hackers Shift to Autonomous AI Cyberattacks

Google's GTIG Q2 2026 report reveals that state-backed and criminal actors are deploying autonomous AI agents and advanced evasion tactics, drastically reducing cyber defense response times.

MakoAuthor: דיגיטל
Source
Google Report: State Actors and Hackers Shift to Autonomous AI Cyberattacks
Photo: Mako / צילום: saeediex, shutterstock

Google's Threat Intelligence Group (GTIG) published its Q2 2026 cyber threat report on Tuesday, revealing that hostile actors and state-sponsored groups have shifted from basic generative AI usage to deploying AI agents and autonomous processes that significantly reduce cyber defenders' reaction times. The report focuses on Iranian activities expanding AI usage for attacks, influence operations, and infrastructure, alongside campaigns by Chinese state-backed groups and financially motivated cybercriminals.

According to the report, the state-backed Iranian threat group CALANQUE ION, also known as APT42, continues to expand its use of large language models, including Gemini. Alongside gathering open-source intelligence and rapidly translating content for targeted phishing messages, group members use AI to develop tactical attack infrastructure and attempt to reverse-engineer software licensing algorithms in order to bypass organizational EDR defense systems.

Iranian Influence Operations and Autonomous Agents

Iran's influence operations apparatus has also been upgraded, according to Google. Rather than relying on simple instructions, Iranian actors use models to draft detailed technical prompts for image generators, including camera angles, studio lighting, and skin textures, to create fake photorealistic personas for social networks. Simultaneously, they instruct models to adopt personas such as psychological warfare experts or oil market analysts, integrating persuasion techniques and psychological manipulation into messages serving Tehran's regime interests.


Google GTIG Q2 2026 findings:

- CALANQUE ION (APT42) uses AI for tactical infrastructure and EDR bypass.

- Financially motivated actors deployed automated vulnerability scanning via Agentic AI in under 6 hours.

- Chinese group UNC6508 exploits compromised cloud environments to run local open-weight AI models.

The report also describes a shift toward autonomous AI agents—Agentic AI—capable of making decisions, troubleshooting in real time, and operating independently. During the second quarter of 2026, Google identified a case where a financially motivated attacker used a chatbot, a simple prompt, and a dedicated set of instructions to plan, build, and execute a vulnerability scanning and mass password-theft campaign in under six hours from initial intrusion into the victim's cloud resources.

«At this point, we can assume that all hostile actors are using AI to some degree, and their activity has significantly improved from these capabilities,» said John Hultquist, chief analyst at Google Threat Intelligence Group.

Evasion Tactics and Chinese Cyber Espionage

Another trend highlighted in the report involves the financial cyber group UNC6780, also known as TeamPCP. According to Google, group members embedded textual notes with extreme prompts—such as requests to develop biological or nuclear weapons—inside malicious code files to trigger safety mechanisms of language model-based security scanners. When a scanner encounters such text, it may refuse to analyze the file due to a safety policy violation, allowing the underlying malicious code to evade scanning and execute within the development environment.

Alongside Iran, the report points to a prolonged cyber espionage campaign by the Chinese threat group UNC6508, targeting academic, medical, and military research institutions in North America. According to Google, the group focuses on stealing proprietary artificial intelligence research, breaking into victims' cloud environments to set up local open-weight models. By doing so, it exploits the compromised organization's computing resources, bypasses commercial API monitoring mechanisms, and continues to research vulnerabilities in AI models themselves.

Google stated that the company is working to block and neutralize the identified activities. According to the firm, all attempts by threat groups to use its artificial intelligence models triggered safety and prevention mechanisms, and the accounts and projects associated with these activities were permanently blocked. In addition, Google DeepMind uses insights from the attack attempts to strengthen safety filters and models.

Related News