DomainFork
Markets
MarketsCompaniesCryptoCommoditiesIslamic Finance
Money
Personal FinanceProperty
World
MalaysiaASEANAsiaWorld
Business
TechnologyStartupsOpinion
Intelligence
AI EdgeOSINT Desk
Media
VideoAudioLifestyle
Breaking
Plant Maintenance & Catalyst Handling ServicesBe our Express Store PartnerKEMPEN DERMA DARAH ANJURAN 99 SPEEDMART KE-15 11/07/202699 Speed Mart Sumbang RM500,000 Sokong Rawatan Dialisis 11/04/2026Diverse and Inclusive WorkforceThreat Intelligence Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise By Google Threat Intelligence Group • 18-minute readAI is changing the economics of vulnerability discovery. Defenders should adapt nowLeading experts, researchers and educators on nuclear disarmament.Observation (CEACR) – adopted 2024, published 113rd ILC session (2025)EXAMPLEARTICLEEkoTitiwangsaMajor Economic Indicators Latest NumbersNewsletterສຳມະນາການປັບປຸງສຳນວນສຳເນົາຂໍ້ມູນສະຖິຕິ ແລະ ການເຜີຍແຜ່ຂໍ້ມູນສະຖິຕິໃນລະບົບ e-GDDSCorporate Governance StatementAsia's semiconductor cycle tracks AI demand and inventory disciplineAI Edge Daily Briefing — 6 August 2026AI Edge Daily Briefing — 4 August 2026AI Edge Daily Briefing — 5 August 2026OSINT Synthesis — 24 July 2026Plant Maintenance & Catalyst Handling ServicesBe our Express Store PartnerKEMPEN DERMA DARAH ANJURAN 99 SPEEDMART KE-15 11/07/202699 Speed Mart Sumbang RM500,000 Sokong Rawatan Dialisis 11/04/2026Diverse and Inclusive WorkforceThreat Intelligence Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise By Google Threat Intelligence Group • 18-minute readAI is changing the economics of vulnerability discovery. Defenders should adapt nowLeading experts, researchers and educators on nuclear disarmament.Observation (CEACR) – adopted 2024, published 113rd ILC session (2025)EXAMPLEARTICLEEkoTitiwangsaMajor Economic Indicators Latest NumbersNewsletterສຳມະນາການປັບປຸງສຳນວນສຳເນົາຂໍ້ມູນສະຖິຕິ ແລະ ການເຜີຍແຜ່ຂໍ້ມູນສະຖິຕິໃນລະບົບ e-GDDSCorporate Governance StatementAsia's semiconductor cycle tracks AI demand and inventory disciplineAI Edge Daily Briefing — 6 August 2026AI Edge Daily Briefing — 4 August 2026AI Edge Daily Briefing — 5 August 2026OSINT Synthesis — 24 July 2026
Home/Intelligence
Economy

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Visibility and context on the threats that matter most. Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response enga

Source: Google Threat Intelligence · August 6, 2026 at 2:54 PM · AI-assisted report

KUALA LUMPUR, 6 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Headline: GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access Lead: Visibility and context on the threats that matter most. Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response enga Body: Visibility and context on the threats that matter most. Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the following developments: Vulnerability Discovery and Exploit Generation: For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI. The criminal threat actor planned to use it in a mass exploitation event but our proactive counter discovery may have prevented its use. Threat actors associated with the People’s Republic of China (PRC) and the Democratic People's Republic of Korea (DPRK) have also demonstrated significant interest in capitalizing on AI for vulnerability discovery. AI-Augmented Development for Defense Evasion: AI-driven coding has accelerated the development of infrastructure suites and polymorphic malware by adversaries. These AI-enabled development cycles facilitate defense evasion by enabling the creation of obfuscation networks and the integration of AI-generated decoy logic in malware that we have linked to suspected Russia-nexus threat actors. Autonomous Malware Operations: AI-enabled malware, such as PROMPTSPY, signal a shift toward autonomous attack orchestration, where models interpret system states to dynamically generate commands and manipulate victim environments. Our analysis of this malware reveals previously unreported capabilities and use cases for its integration with AI. This approach allows threat actors to offload operational tasks to AI for scaled and adaptive activity. AI-Augmented Research and IO: Adversaries continue to leverage AI as a high speed research assistant for attack lifecycle support, while shifting toward agentic workflows to operationalize autonomous attack frameworks. In information operations (IO) campaigns, these tools facilitate the fabrication of digital consensus by generating synthetic media and deepfake content at scale, exemplified by the pro-Russia IO campaign “Operation Overload.” Obfuscated LLM Access: Threat actors now pursue anonymized, premium tier access to models through professionalized middleware and automated registration pipelines to illicitly bypass usage limits. This infrastructure enables large scale misuse of services while subsidizing operations through trial abuse and programmatic account cycling. Supply Chain Attacks: Adversaries like "TeamPCP" (aka UNC6780) have begun targeting AI environments and software dependencies as an initial access vector. These supply chain attacks result in multiple types of machine learning (ML)-focused risks outlined in the Secure AI Framework (SAIF) taxonomy, namely Insecure Integrated Component (IIC) and Rogue Actions (RA). Our analysis of forensic data associated with these attacks reveals threats actors attempting to pivot from compromised AI software to broader network environments for initial access and to engage in disruptive activities, such as ransomware deployment and extortion. Attackers rarely shy away from experimentation and innovation, but neither do we. In addition to sharing our findings and mitigations with the larger security and AI community, Google employs proactive measures to stay ahead of these constantly changing threats. Google enhances our products’ safeguards to offer scaled protections to users. For Gemini, we mitigate model abuse by disabling malicious accounts. We leverage AI agents like Big Sleep to identify software vulnerabilities and use Gemini’s reasoning capabilities via the likes of CodeMender to automatically fix them, proving that AI can also be a powerful tool for defenders. Threat actors are leveraging AI to augment various phases of the attack lifecycle. This includes supporting the development of vulnerability exploits and malware, facilitating autonomous execution of commands, enabling more targeted and well-researched reconnaissance, and improving the efficacy of social engineering and information operations. As the coding capabilities of AI models advance, we continue to observe adversaries increasingly leverage these tools as expert-level force multipliers for vulnerability research and exploit development, including for zero-day vulnerabilities. While these tools empower defensive research, they also lower the barrier for adversaries to reverse-engineer applications and develop sophisticated, AI-generated exploits. While we observe a variety of threat actors leveraging AI for vulnerability research, we noted a particular interest from several clusters of threat activity associated with the People’s Republic of China (PRC) and the Democratic People's Republic of Korea (DPRK). These actors have leveraged sophisticated approaches toward AI-augmented vulnerability discovery and exploitation, beginning with persona-driven jailbreaking attempts and the integration of specialized, high-fidelity security datasets to augment their vulnerability discovery and exploitation workflows. In a more sophisticated use case, we observed threat actors experiment with a specialized vulnerability repository hosted on GitHub known as “wooyun-legacy.” The project is designed as a Claude code skill plugin that integrates a distilled knowledge base of over 85,000 real-world vulnerability cases collected by the Chinese bug bounty platform WooYun between 2010 and 2016. By priming the model with vulnerability data, it facilitates in-context learning to steer the model to approach code analysis like a seasoned expert and identify logic flaws that the base model might otherwise fail to prioritize. In their pursuit of this vulnerability research, we see clear indications of automation and scaled research. In addition to leveraging individual prompts for real-time troubleshooting, we have observed APT45 sending thousands of repetitive prompts that recursively analyze different CVEs and validate PoC exploits. This results in a more arsenal of exploit capabilities that would be impractical to manage without AI assistance. To facilitate these activities, actors are also experimenting with agentic tools such as OpenClaw and OneClaw alongside intentionally vulnerable testing environments. The use of these tools alongside vulnerability research suggests an interest in… (AI-assisted rewrite, based on the original source)

Related: Google

Malaysia Impact

Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.

Reporting based on Google Threat Intelligence. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.

Suggested Reads

Plant Maintenance & Catalyst Handling ServicesBe our Express Store PartnerKEMPEN DERMA DARAH ANJURAN 99 SPEEDMART KE-15 11/07/202699 Speed Mart Sumbang RM500,000 Sokong Rawatan Dialisis 11/04/2026

Analyst Consensus — This Week

Bullish6.6/10AI sentiment across 96 stories · not investment advice

The Daily Brief · Free

Five market signals.
Five minutes. Every morning.

AI-curated intelligence on Malaysia, ASEAN, and global markets — before the opening bell.

  • ✓ KLCI, ringgit & sector movers
  • ✓ The AI Edge sentiment read
  • ✓ No spam — one email, weekday mornings

Free daily market briefing. No spam, unsubscribe anytime.

DomainFork

Malaysian financial intelligence — AI-assisted coverage of finance, economics, technology, and open-source data across Malaysia, ASEAN, and the world.

Sections

  • Malaysia
  • ASEAN
  • Asia
  • World
  • Tech
  • Markets

Intelligence

  • AI Daily Briefing
  • OSINT Desk
  • Video
  • Audio

Company

  • About Us
  • Editorial Standards
  • Advertise
  • Contact the Desk

Disclaimer: DomainFork provides financial, economic, technology, and OSINT information for general education and research. AI summaries, sentiment scores, and market data are not investment advice. Consult a licensed professional before making financial decisions.

© 2026 DomainFork. All rights reserved.

Powered by: Codint Technology : codint.io