GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented Operations — Threadlinqs Intelligence
As of 2026-05-30, GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented Operations is a high-severity apt threat attributed to APT27 (China, North Korea, Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-0495 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT27 · China, North Korea, Russia · ESPIONAGE
Google Threat Intelligence Group's May 11, 2026 AI Threat Tracker documents the first identified threat-actor use of an AI-developed zero-day exploit — a Python script that bypassed two-factor
On May 11, 2026, Google Threat Intelligence Group (GTIG) published its Q2 2026 AI Threat Tracker, the first authoritative confirmation that a threat actor has weaponized a zero-day vulnerability developed with the assistance of a large language model. The exploit — a Python script bypassing two-factor authentication on a popular, intentionally unnamed open-source web-based system administration tool — targeted a semantic logic flaw in which a developer hardcoded a trust assumption that contradicted the application's own 2FA enforcement logic. Such high-level reasoning bugs are precisely the class of flaw modern frontier LLMs excel at surfacing and which traditional static-analysis and fuzzing tooling consistently misses. The script bore unmistakable AI authorship markers: an abundance of educational docstrings, a hallucinated CVSS score in inline comments, textbook Pythonic structure characteristic of LLM training-data style, detailed help menus, and a clean ANSI color class implementation. A prominent cyber-crime threat actor was preparing a mass-exploitation campaign against vulnerable internet-exposed instances; GTIG independently discovered the script, disrupted operator infrastructure, and pursued responsible disclosure with the affected vendor. Google explicitly ruled out Gemini as the originating LLM but did not name the specific model used.
The tracker further documents five AI-enabled malware families. PROMPTFLUX (VT hash eb0687daed29f3651c61b0a2aa4a0cdcf2049a1ebae2e15e2dd9326471d318a1) calls the Gemini API at runtime to mutate its own source code on demand, enabling polymorphic evasion of static signature engines. HONESTCUE (VT collection malware--77a0b844-02bb-563c-b8fd-304f93e11ef1) likewise queries Gemini to generate fresh VBScript obfuscation and evasion routines per execution. CANFAIL (VT collection malware--30f26e32-0393-5023-92ef-f677f1def61c) and LONGSTREAM (VT collection malware--6cae6e39-72de-5b9e-aebe-47243e3dc63a) — both attributed to suspected Russia-nexus actors targeting Ukrainian organizations — embed AI-generated benign-looking decoy logic, with LONGSTREAM samples containing 32+ repeated daylight-saving-time queries and other inert administrative tasks specifically intended to dilute analyst attention and frustrate behavioral analytics; LLM-authored developer comments in CANFAIL explicitly annotate the inert padding. PROMPTSPY (Android), previously documented by ESET, now features a GeminiAutomationAgent module that calls generativelanguage.googleapis.com with the gemini-2.5-flash-lite model to autonomously navigate device UI. The agent serializes the live Android Accessibility-API view hierarchy into XML, supplies a benign-persona hardcoded prompt designed to defeat safety filters, and returns structured JSON CLICK/SWIPE actions with precise spatial coordinates derived by the model from in-prompt geometric reasoning; complementary modules implement reverse-TCP tunneling, FCM-based relaunch, dynamic VNC-relay and Gemini API key updates, biometric-replay attacks, and an AppProtectionDetector that draws an invisible overlay over the system uninstall button.
Five nation-state and uncategorized clusters are profiled. APT27 (PRC) used Gemini to accelerate development of a fleet-management application underpinning an ORB (operational relay box) network supporting MOBILE_WIFI and ROUTER device types, 4G/5G SIM-card residential-IP rotation, and a maxHops=3 multi-hop proxy topology. APT45 (DPRK) issued thousands of repetitive prompts to recursively analyze CVEs and validate PoC exploits, and is observed using OpenClaw and OneClaw agentic frameworks plus disposable vulnerable test environments. UNC2814 (PRC) leveraged expert-persona prompting (senior security auditor / C/C++ binary security expert) against TP-Link router firmware and Odette File Transfer Protocol implementations seeking pre-auth RCE primitives. UNC5673 (PRC; overlap with TEMP.Hex) targets South and Southeast Asian governments and operates ob
Weaknesses (CWE)
CWE-287, CWE-307, CWE-798, CWE-840, CWE-506, CWE-1357
Target sectors: government, defense, technology, telecommunications, financial services, media, software supply chain, cloud / AI service providers, managed service providers, research
Target regions: South Asia, Southeast Asia, Ukraine, Europe, North America, East Asia, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1592, T1591, T1591, T1587, T1587, T1588, T1588, T1588, T1588, T1583