THEMETASEC

Cybersecurity News, Aggregated

Threat actors are coming for your AI assets to operationalize their use of AI

CSO Online · 2 hours ago Breach

Both state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of LLMs is being extracted with targeted prompts, is increasing. “GTIG observed adversaries with wide-ranging motivations target proprietary AI models and source code, exfiltrate application programming interface (API) credentials, and co-opt victim cloud environments to sustain unauthorized AI workloads,” the Google Threat Intelligence Group (GTIG), said in their latest quarterly AI Threat Tracker report released last week. “This shift underscores that enterprise AI assets — from model weights to cloud compute quotas — are high-value targets for espionage, extortion, and resource theft.” This threat activity didn’t affect just AI labs, but also government, military, healthcare, and media organization that might train or fine-tune their own models. Even if they don’t do any AI model development themselves, organizations might have a lot of valuable AI-related proprietary data on their systems, from RAG pipelines to custom workflows, agents, and credentials. AI credentials in the crosshairs Back in June, GTIG warned about a China-based cyberespionage group tracked as UNC6508 that targeted organizations involved in academic, healthcare, and defense research. The information collected by this group included AI research. UNC6508 was also seen compromising cloud environments to deploy LLM infrastructure for its own use, researching how to deploy LLMs locally and investigating vulnerabilities in AI models. During the second quarter of 2026, Google’s Mandiant incident response arm investigated breaches by data extortion groups that involved theft of AI models, skills, prompts, source code, and related research. In one case, a threat actor breached a healthcare organization and stole drug research and other corporate data, including a proprietary AI model. In a separate incident, attackers compromised an AI media generation company and stole proprietary source code, prompts, skills, model scripts, and secrets. GTIG also warns in its report about an increase in model distillation attack campaigns against Google’s own AI models. These attacks attempt to extract model outputs for targeted prompts to train other models on those outputs. Google observed campaigns involving more than 100 million prompts targeting audio, video, and image generation capabilities. These campaigns are launched through proxy networks using thousands of compromised account credentials. The US National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory last week accusing China-based AI labs of engaging in industrial-scale distillation against US frontier AI models. “Businesses not directly associated with frontier AI models may be tempted to disregard these campaigns as irrelevant due to them being a national security issue, but the exposure of model access to customers or partners makes API keys and service accounts valuable targets, with abuse of access to those models appearing as legitimate,” Ismael Valenzuela, VP of labs, threat research, and intelligence at Arctic Wolf, tells CSO. Attackers increasingly leverage agentic AI In addition to using stolen AI-related credentials for distillation campaigns, hackers also need them for automating other offensive operations that include a high level of automation via AI agents. Mandiant observed a financially motivated threat actor use compromised cloud infrastructure credentials to deploy an autonomous multi-agent attack framework. The resources enabled the attacker to plan, build, and execute a mass credentials harvesting campaign in less than 6 hours. “Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials,” the researchers said. “The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute Internet Protocol (IP) rotation logic without manual intervention — significantly reducing the human-in-the-loop latency.” The GTIG researchers also uncovered an automated reconnaissance and credential management framework called Recon that was being used on a live command-and-control server to manage more than 23,000 stolen credentials, including API keys for cloud infrastructure and AI services. A Chinese threat actor known for targeting government organizations was also observed building an AI-powered exploitation and post-exploitation pipeline, automating the entire attack chain from reconnaissance to credential scraping for lateral movement. “GTIG continues to observe the widespread adoption and incorporation of AI technologies by threat actors with wide-ranging motivations across multiple geographic portfolios,” the researchers said. “Threat actors continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration. Key examples from the last quarter include PRC- and Russia-nexus espionage groups; financially-motivated and espionage-related activity attributed to the Democratic People’s Republic of Korea (DPRK); financially-motivated cyber crime groups; and state-sponsored IO [influence operations] groups.” Some examples of such groups include: BASIN CASTLE, a China-based group also known as BASIN or TEMP.Hex CALANQUE ION, an Iranian state-sponsored actor also tracked as APT42 RAVINE CASTLE, a Chinese cyber espionage group also known as COULEE or APT24 SANDWORM RELIC, a Russian state-linked cyber espionage actor also known as SANDWORM and APT44 UNC6240, a data theft extortion group also known as ShinyHunters MIDNIGHT NEPTUNE aka UNC1069, a North Korean threat group known for stealing cryptocurrency “In order to experiment with generative AI tools, threat actors must obtain and maintain access to those tools,” the researchers explain. “The cost of premium model access and high-performance compute is one of the primary barriers for threat actors seeking to operationalize AI. This has resulted in increased targeting, exfiltration, and sale of AI accounts across cyber crime communities coupled with a growing number of intrusions involving the compromise of enterprise cloud environments to hijack compute resources (aka ‘LLMJacking’).”

Read full story at CSO Online →