Sophia
Hart

Autonomous AI Cyberattack: Credential Theft in Under Six Hours

Sophia Hart

Sep 9, 2026

6 min read

autonomous ai cyberattack

TL; DR

  • A financially motivated actor used an autonomous AI framework to harvest thousands of credentials in six hours. It managed scanning, troubleshooting, and IP rotation without human input after accessing cloud infrastructure.
  • TeamPCP (aka Altered Spider, UNC6780) deploys SANDCLOCK against Linux and Kubernetes after supply-chain compromises against PyPI, npm, and Docker Hub. Its successor DUSTMAKER targets CI/CD pipelines and adds AI-assistant workspace poisoning with prompt injection to evade AI-assistant defenses.
  • GTIG also reported attackers targeting proprietary AI models in healthcare, government, and media. The activity includes exfiltrating API credentials and hijacking cloud environments for unauthorized AI workloads.
  • Harvested credentials and AI access are being resold or used in ransomware and extortion partnerships.

Google Threat Intelligence Group (GTIG) disclosed a case involving an autonomous AI cyberattack. A financially motivated actor compromised thousands of third-party credentials in under six hours after breaching an organization’s cloud infrastructure. The system, run through an AI coding chatbot with agent instructions, autonomously handled scanning, troubleshooting, and IP rotation.

The disclosure also describes a separate campaign by TeamPCP, also tracked as Altered Spider and UNC6780. The group has run supply-chain compromises against PyPI, npm, and Docker Hub. It followed these with the SANDCLOCK and DUSTMAKER stealers at different stages. Public reporting does not link this campaign to the six-hour incident above, so this briefing treats them separately.

Both cases show the same problem. Agentic AI compresses the gap between compromise and large-scale credential exposure, shrinking the window defenders have to respond.

Book a free demo and explore Hexnode today!

Inside the six-hour credential harvesting campaign

GTIG attributed this incident to a financially motivated actor, distinct from TeamPCP. The attacker first compromised an unnamed organization’s cloud infrastructure. From there, the operation relied on:

  • An AI coding chatbot directed by a prompt and a set of agent instructions
  • Preconfigured markdown instruction sets used as operational playbooks
  • Automated scanning and credential harvesting run across the target environment
  • Autonomous management of the vulnerability scanning pipeline, including real-time troubleshooting
  • IP rotation logic executed without human intervention

The result was compromise of thousands of third-party credentials in under six hours. GTIG chief analyst John Hultquist said criminals behind campaigns like this one “will gravitate to attacks that are faster than we can respond to.

TeamPCP’s supply chain compromise and the SANDCLOCK-to-DUSTMAKER shift

TeamPCP compromises PyPI, npm, and Docker Hub, then deploys credential stealers against developer and AI coding assistant environments. It monetizes stolen data via direct sale or ransomware extortion partnerships.

The two stealers GTIG named are functionally distinct, not interchangeable variants:

Threat actors

Entity Scope Operational Risk
Six-hour campaign actor Unnamed financially motivated actor using an autonomous AI agent framework Thousands of third-party credentials compromised before response was possible
TeamPCP (Altered Spider, UNC6780) Runs software supply-chain compromises across PyPI, npm, and Docker Hub Entry point delivering credential stealers into developer pipelines

Tools deployed

Tool Type / Scope Operational Risk
SANDCLOCK Python-based, Linux and Kubernetes, container-escape capable (used March–April 2026) Cloud, developer, and cryptocurrency wallet credential theft
DUSTMAKER Cross-platform JavaScript, CI/CD-optimized (used April 2026 onward) Credential theft, AI-assistant workspace poisoning, prompt injection to evade AI-assistant defenses

SANDCLOCK is a component of what has publicly been called CanisterWorm. It runs on Linux, interacts with Kubernetes, and targets cryptocurrency wallets with container-escape capability. Its successor, DUSTMAKER, is cross-platform, built for CI/CD pipelines, and drops container-escape. GTIG said AI-assistant workspace poisoning and prompt-injection evasion appear only in DUSTMAKER, not in SANDCLOCK.

Why AI assets are becoming primary targets

GTIG’s disclosure also describes a broader pattern separate from either campaign above. Attackers with varied motivations are now targeting proprietary AI models directly.

Observed activity includes:

  • Targeting proprietary AI models across healthcare, government, and media organizations
  • Exfiltrating API credentials tied to AI services
  • Hijacking victim cloud environments to run unauthorized AI workloads

Separately, GTIG reported a China-nexus group using AI tools such as Claude, Gemini, and Codex to write exploit scripts, generate spear-phishing lures, and debug operations mid-intrusion.

This shift raises the stakes for any organization running developer tooling, CI/CD pipelines, or AI coding assistants against production cloud environments, since each of those surfaces can now double as an entry point for credential theft.

introduction-to-hexnode-xdr-300x168

Introduction to Hexnode XDR

Hexnode XDR delivers cross-endpoint correlation and a unified dashboard, integrating with UEM to strengthen defenses

DOWNLOAD

Where endpoint defense fits

Hexnode’s role here is bounded to the endpoint layer. It does not extend to the cloud, registry, or pipeline layers where most of this activity occurs.

UEM

  • Hexnode UEM handles patch and configuration management on Windows, macOS, and Linux developer endpoints.
  • Application inventory and blocklisting help flag unauthorized or unapproved software on the endpoints developers actually use.

XDR

  • Threat detection and response across Windows and macOS developer endpoints fall to Hexnode XDR.
  • It feeds real-time threat signals directly into Hexnode IdP via a single native agent, triggering instant access revocation without needing third-party integration glue.

IdP

  • Hexnode IdP enforces compliance-based access, blocking logins from devices that are not enrolled in UEM or fail compliance checks.
  • It applies continuous Zero-Trust verification, revoking application access mid-session if device compliance drifts or Hexnode XDR flags a threat.

Documented boundary

None of this extends to PyPI, npm, or Docker Hub registries, Kubernetes clusters, CI/CD pipeline logs, or cloud provider environments. Endpoint hardening complements, but does not replace, supply-chain scanning and cloud identity and access controls.

Endpoint hygiene is not supply chain security

Confirm developer workstations run current security updates. Verify software inventory policies flag unapproved package managers or unsigned binaries. These steps reduce the local attack surface. They do not substitute for supply-chain package scanning, cloud IAM hardening, or CI/CD secrets rotation, since those controls sit outside the endpoint entirely.

FAQs

No confirmed link exists. GTIG describes them as separate, financially motivated operations, and public reporting does not establish a connection between the two.

SANDCLOCK targets Linux and Kubernetes with container-escape capability. DUSTMAKER is its cross-platform JavaScript successor, built for CI/CD pipelines, and adds AI-assistant workspace poisoning and prompt-injection evasion that SANDCLOCK did not have.

Patching alone does not address supply-chain compromise or autonomous credential harvesting. Organizations also need package integrity checks, CI/CD secrets governance, and endpoint hardening as separate, complementary controls.

Conclusion

Agentic AI now gives attackers speed and consistency that manual operations cannot match, shrinking the gap between initial access and large-scale credential exposure to a matter of hours. Enterprises should treat automated detection, tighter secrets governance, and identity-aware access controls as baseline requirements, not future upgrades.

Endpoint hardening plays a supporting role in this picture, particularly for developer and administrator devices, but it works alongside cloud, identity, and supply-chain controls rather than in place of them.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.