GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
2026-09-08 • Google •
GTIG observed at least one DPRK IT worker cluster registering LLM APIs in bulk through hijacked accounts to scale its operations. DPRK-linked clusters also used LLM prompts to profile aerospace and defense targets and generate fabricated resumes, job descriptions, and recruiter personas for social engineering. Midnight Neptune, financially motivated North Korea-nexus clusters formerly tracked as UNC1069, increasingly used commercial LLMs and open-weight models to support cryptocurrency theft through social engineering, software supply chain manipulation, and automated backdoor development. Its activity included AI-assisted Python RAT development, Bash scripting for lateral movement, poisoned repository configurations, altered Claude CLI hooks, and deployment of the SOMBERMEME backdoor.