AI has compressed attacker tempo, not attacker capability
Google's threat intelligence group records agent-driven credential harvesting completed in under six hours. Unit 42 found that roughly 97% of AI-related malware samples never left a sandbox. Both findings hold, and the gap between them is where defensive effort belongs.

Two findings that appear to contradict each other
The Google Threat Intelligence Group published its AI threat tracker on 8 September 2026 [1]. It describes a progression from basic prompting through agentic workflows to AI-enabled automation, and records that in the second quarter of 2026 threat actors compromised cloud resources and then planned, built and executed agent-enabled mass credential harvesting in under six hours [1]. One exposed command-and-control server held over 23,800 harvested secrets, including cloud and AI service API keys [1].
Unit 42 published a study of AI-enabled malware on 25 August 2026 [2]. It analysed 405 samples integrating AI capabilities, drawn from WildFire reports, VirusTotal Intelligence and open-source research. Twelve samples, roughly 3%, appeared on protected endpoints; approximately 97% existed only in sandboxes and on VirusTotal [2]. Every sample that reached a customer environment was detected and blocked by existing controls: sandbox detonation, behavioural analytics, code-signing anomaly detection and entropy analysis [2].
The AI component does not evade detection. It changes how the code is authored, not how it executes.
Unit 42, The State of AI-Enabled Malware, August 2026 [2]
These findings are not in conflict. They measure different things. GTIG measures operational tempo; Unit 42 measures malware efficacy against deployed controls. Evidence for improvement in the first is strong. For the second it is absent.
Where the tempo gain is real
Mandiant's M-Trends 2026, drawn from over 500,000 hours of investigation across 2025, records the median interval between initial access and hand-off to a follow-on group at 22 seconds, against more than eight hours in 2022 [3][4]. Unit 42's 2026 Global Incident Response Report puts the fastest quartile of intrusions at roughly 72 minutes to exfiltration, down from 285 minutes in 2024, and a simulated AI-assisted attack at 25 minutes [5].
A Unit 42 investigation published on 2 September 2026 describes an intrusion in which autonomous agents compromised an enterprise network in under ten hours, spanning more than 50 MITRE ATT&CK techniques across initial access, reconnaissance, credential harvesting from code repositories, secrets manager access and CI/CD pipeline compromise [6]. Unit 42 assesses equivalent human work would normally take around two weeks [6].
The detection guidance from that case is specific: parallel LLM calls to multiple frontier providers from one environment, structured Markdown files passing state between agents, and custom scripts assessed as AI-generated [6].
Where the gain is not
The same research shows autonomous tooling performing poorly at the decisive part.
Unit 42's July 2026 analysis of a Chinese-speaking operator running DeepSeek through an agent framework is the clearest case [7]. Scanning identified 647,017 n8n instances globally, 25,209 of them in China. The agent sampled roughly 100 addresses, probed about 40 for version information, and found three vulnerable instances. Every exploitation attempt failed on authentication requirements [7]. A parallel phase against Langflow enumerated 84 instances, identified one vulnerable target, and also failed [7].
The confirmed successes were manual: data exfiltrated from three organisations through a Citrix NetScaler flaw, command execution on eleven endpoints, reverse shell attempts against nine servers [7]. Unit 42 notes the operator appeared to let the model narrow targeting to conserve compute, compressing what it describes as hundreds of hours of analysis into minutes [7]. The campaign included persistent manual targeting of a Malaysian government entity across multiple days, with refined parameters and proxy anonymisation [7]. The automation ran the survey. A person conducted the intrusion.
Unit 42's 3 September report on Latin American targeting has the same texture [8]. Operators used Claude and GPT-4.1 through self-hosted NextChat instances against transportation bodies, government ministries and municipal water utilities in Mexico and Ecuador, and the financial sector in Brazil [8]. The activity was exposed because a NextChat directory was left open to the internet [8]. Command histories show trial and error: nine successive versions of a Go-based SOCKS5 proxy within two hours [8]. Unit 42 tracks the clusters as CL-CRI-1131 and CL-CRI-1163, describing technical overlaps rather than asserting attribution [8].
Google's February 2026 position was that AI had augmented existing attack methods rather than created fundamentally new ones [11]. The September tracker revises the tempo finding but not that conclusion: GTIG states it has not yet observed fully autonomous zero-day discovery and exploitation pipelines deployed in the wild, and that in observed influence operations it saw no evidence of successful automation or breakthrough capability [1]. Mandiant is equally direct: it does not consider 2025 the year breaches were the direct result of AI [3].
What is genuinely new
Three developments are not simply faster versions of existing tradecraft.
- Runtime model queries. GTIG and Mandiant both record malware calling a language model during execution. PROMPTFLUX rewrites its code hourly through the Gemini API; PROMPTSTEAL, which Mandiant attributes to APT28, generates Windows commands for document theft in live operations [4][3]. GTIG adds DUSTMAKER, a credential stealer embedding prompt-injection text intended to defeat LLM-based security scanners [1].
- AI infrastructure as a target. GTIG records infostealers collecting AI developer configurations and API keys, underground prices for AI accounts more than doubling in 2026, distillation campaigns exceeding 100 million prompts against Gemini, and a PRC-nexus actor tracked as UNC6508 deploying local models inside victim infrastructure to avoid API-side monitoring [1].
- Volume in influence operations. Anthropic's September 2026 report, covering December 2025 to August 2026, documents nine influence operations of Russian, Iranian, Turkish and Gulf and African origin, including one using roughly 70 fake news sites and over 250 inauthentic accounts, and an election-manipulation platform marketed in Malaysia as military-grade, AI-driven infrastructure [9]. The caveat matters: most content drew little or no authentic engagement [9].
Set against these, the deepest access in 2026 reporting owes nothing to AI: Rapid7 Labs reported in March 2026 on a China-nexus actor it tracks as Red Menshen using a kernel-level BPFdoor implant in telecommunications networks and targeting SCTP signalling for subscriber tracking, which it characterises as deliberate pre-positioning [12].
What to do
- Re-baseline containment targets against hand-off, not dwell time. A 22-second median makes response plans built around hours the wrong instrument [3][4].
- Instrument outbound access to model APIs from server workloads. Runtime LLM calls are visible at the network layer, and parallel calls to multiple providers is a named pattern [6][1].
- Treat AI developer credentials as privileged. API keys, agent configurations and MCP server definitions belong in the same tier as cloud administrative credentials [1].
- Do not re-tool for AI malware. Current controls detect it [2]. Spend instead on the vectors that produce breaches: exploitation at 32% of intrusions with an identified vector, and voice phishing at 11%, rising to 23% in cloud intrusions [3][4].
- Rehearse the social-engineering path. Mandiant's UNC3753 reporting describes vishing-led intrusions running from first contact to extortion within one business day, and recommends restricting virtual desktop access to corporate-owned devices [10].
- Expect operational security failures. In three cases above, the campaign was exposed because the operator left AI infrastructure open to the internet [1][7][8].
Domain view
The defensible reading of 2026 is that AI has removed labour from the parts of an operation that were already cheap, and not yet from the parts that were expensive. Anthropic's framing, that AI has collapsed the labour and tooling gap separating state-sponsored operations from individual actors, is a statement about who can attempt an operation rather than what one can achieve [9].
Two details deserve regional attention. The Malaysian government entity in the Unit 42 case was targeted manually, not autonomously [7]; the automation was a survey instrument, and a person still made the decisions. And an election-manipulation service was marketed into Malaysia on the strength of its AI claims [9]. Both point the same way: claims about AI capability are running ahead of demonstrated effect, including in the criminal market's own advertising.
The discipline is to act on the measured change, which is tempo, and discount the rest until it appears in telemetry. That is not a reason to relax. A six-hour credential harvesting campaign and a 22-second hand-off are severe problems on their own terms. They are simply not the problems AI-specific security products are sold to solve.
Sources
Every R3KONX article cites its primary material. 12 sources, in order of first citation. Links open the original publication.
- GTIG AI Threat Tracker: From Prompting to Autonomy - The Evolution of Adversarial AI Google Threat Intelligence Group · 2026-09-08
- The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Unit 42, Palo Alto Networks · 2026-08-25
- M-Trends 2026 Report: Executive Edition Mandiant / Google Cloud · 2026
- Twenty-Two Seconds to Hand-Off: Inside Mandiant's M-Trends 2026 Findings ComplexDiscovery · 2026
- 2026 Unit 42 Global Incident Response Report Unit 42, Palo Alto Networks · 2026-02
- An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation Unit 42, Palo Alto Networks · 2026-09-02
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Unit 42, Palo Alto Networks · 2026-07-30
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Unit 42, Palo Alto Networks · 2026-09-03
- Countering misuse of AI: September 2026 Anthropic · 2026-09
- Ongoing Targeted Campaign Against US Law Firms (UNC3753) Mandiant / Google Threat Intelligence Group · 2026-06-05
- Google Threat Intelligence Group reports on AI threat trends Google · 2026-02-12
- Rapid7 Labs Identifies State Sponsored Sleeper Cells Embedded in Global Telecommunications Networks Rapid7 · 2026-03-26
Researched and written by the R3KONX Analysis Desk from the cited primary material, with AI assistance in research and drafting. Methodological caveat: the vendor telemetry compared here is drawn from different visibility (endpoint protection estates, model provider enforcement logs and incident response engagements) and the resulting figures are not directly comparable; each is reported with its source. Attribution and tracking names are the assessments of the named researchers, not independent R3KONX findings. Corrections to event@r3konx.asia.
