GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

2026-09-08 Google

https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai

Thumbnail for GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

GTIG observed at least one DPRK IT worker cluster registering LLM APIs in bulk through hijacked accounts to scale its operations. DPRK-linked clusters also used LLM prompts to profile aerospace and defense targets and generate fabricated resumes, job descriptions, and recruiter personas for social engineering. Midnight Neptune, financially motivated North Korea-nexus clusters formerly tracked as UNC1069, increasingly used commercial LLMs and open-weight models to support cryptocurrency theft through social engineering, software supply chain manipulation, and automated backdoor development. Its activity included AI-assisted Python RAT development, Bash scripting for lateral movement, poisoned repository configurations, altered Claude CLI hooks, and deployment of the SOMBERMEME backdoor.

Related Actors

Related Reports

« Back