Mandiant: Adversaries Accelerate AI Misuse, Shifting to Autonomous Operations
Mandiant's latest AI Threat Tracker reveals threat actors are rapidly evolving their use of AI, moving from basic prompting to autonomous agentic workflows and sophisticated supply chain attacks.

Threat actors are increasingly leveraging artificial intelligence (AI) tools, transitioning from simple prompt injection techniques to more advanced, autonomous agentic workflows, according to a new report from Google Threat Intelligence Group (GTIG), formerly Mandiant.
The GTIG AI Threat Tracker details how adversaries are compressing the traditional response window for defenders by reducing human-in-the-loop latency. In one observed incident during Q2 2026, threat actors successfully compromised a cloud resource and then orchestrated a mass credential harvesting campaign using AI agents in under six hours.
Beyond direct exploitation, threat actors are also actively targeting AI assets themselves. This includes compromising proprietary AI models and source code, stealing API credentials, and co-opting victim cloud environments to sustain unauthorized AI workloads. GTIG highlights that enterprise AI assets, from model weights to cloud compute quotas, are now considered high-value targets for espionage, extortion, and resource theft.
The report identifies several key trends, including expanding software supply chain risks due to the integration of AI-assisted coding tools and open-source software. Threat actors are actively targeting developers, AI coding assistants, and LLM security scanners. Furthermore, there's a notable shift towards agentic AI and automation, with adversaries deploying multi-agent frameworks that can autonomously manage scanning pipelines, resolve operational errors, and execute credential harvesting at scale.
AI capabilities are also being used as force multipliers across the entire attack lifecycle by both state-sponsored and cybercrime groups. This ranges from target reconnaissance and social engineering lure creation to custom malware obfuscation and post-exploitation troubleshooting. The report also notes experimentation with scaling information operations (IO) campaigns using AI.
To circumvent access costs and restrictions, adversaries are engaging in illicit account procurement and "LLMJacking." This involves stealing developer credentials, purchasing compromised AI platform accounts, and hijacking enterprise cloud infrastructure to run unauthorized high-performance compute workloads.
Mandiant's analysis is grounded in telemetry from incident response engagements, global threat actor tracking, and live platform defenses. The findings underscore how state-sponsored espionage groups, financially motivated cyber criminals, and information operations actors are operationalizing AI tools in the wild.
Google states its commitment to developing AI responsibly, integrating proactive model-level safeguards, specialized threat intelligence, and targeted containment protocols. The company is continuously hardening its models against misuse, mitigating malicious activity through proactive disruption, and utilizing its autonomous Google AI Threat Defense architecture to operationalize security across enterprise environments.