GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented Operations
GTIG AI Threat Tracker (May 2026) (TL-2026-0495), also tracked as GTIG AI Threat Tracker May 2026, is a high-severity advanced persistent threat campaign, first published 2026-05-11. It is attributed to APT27 (China, North Korea, Russia) with high confidence, affects Unnamed open-source vendor (withheld by GTIG) Web-based system, maps to 28 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0495
- Threat ID
- TL-2026-0495
- Also known as
- GTIG AI Threat Tracker May 2026, Mandiant AI Threat Tracker Q2 2026, First AI-Developed Zero-Day, AI Vulnerability Exploitation Initial Access report
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-05-11
- Last reviewed
- 2026-05-11
- Attribution
- APT27
- Attribution confidence
- HIGH
- Nation-state nexus
- China, North Korea, Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, defense, technology, telecommunications, financial services, media, software supply chain, cloud / AI service providers, managed service providers, research
- Target regions
- South Asia, Southeast Asia, Ukraine, Europe, North America, East Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in GTIG AI Threat Tracker (May 2026)
Malware and tooling: CANFAIL, HONESTCUE, LONGSTREAM, PROMPTFLUX, PROMPTSPY, SANDCLOCK, CLIProxyAPI, Claude-Relay-Service, Hexstrike, ORB network (operational relay box) with maxHops=3, OneClaw, OpenClaw
Google Threat Intelligence Group's May 11, 2026 AI Threat Tracker documents the first identified threat-actor use of an AI-developed zero-day exploit — a Python script that bypassed two-factor authentication on an unnamed open-source web-based system administration tool via a semantic logic flaw, planned for mass exploitation by a criminal actor and disrupted by GTIG. The report also enumerates five AI-enabled malware families (PROMPTFLUX dynamic source-code mutation, HONESTCUE VBScript just-in-time evasion, CANFAIL/LONGSTREAM Russia-nexus AI-generated decoy code targeting Ukraine, and the PROMPTSPY Android backdoor's GeminiAutomationAgent autonomous UI-driving module), AI-augmented operations by PRC-nexus APT27/UNC2814/UNC5673/UNC6201 and DPRK-nexus APT45 (including expert-persona jailbreaking, recursive PoC validation, ORB fleet-management development, and obfuscated LLM-access middleware), TeamPCP (UNC6780) supply-chain compromises of Trivy/Checkmarx/LiteLLM/BerriAI deploying SANDCLOCK credential stealer, and Operation Overload's pro-Russia AI voice-cloning IO campaign.
How GTIG AI Threat Tracker (May 2026) works
On May 11, 2026, Google Threat Intelligence Group (GTIG) published its Q2 2026 AI Threat Tracker, the first authoritative confirmation that a threat actor has weaponized a zero-day vulnerability developed with the assistance of a large language model. The exploit — a Python script bypassing two-factor authentication on a popular, intentionally unnamed open-source web-based system administration tool — targeted a semantic logic flaw in which a developer hardcoded a trust assumption that contradicted the application's own 2FA enforcement logic. Such high-level reasoning bugs are precisely the class of flaw modern frontier LLMs excel at surfacing and which traditional static-analysis and fuzzing tooling consistently misses. The script bore unmistakable AI authorship markers: an abundance of educational docstrings, a hallucinated CVSS score in inline comments, textbook Pythonic structure characteristic of LLM training-data style, detailed help menus, and a clean ANSI color class implementation. A prominent cyber-crime threat actor was preparing a mass-exploitation campaign against vulnerable internet-exposed instances; GTIG independently discovered the script, disrupted operator infrastructure, and pursued responsible disclosure with the affected vendor. Google explicitly ruled out Gemini as the originating LLM but did not name the specific model used.
The tracker further documents five AI-enabled malware families. PROMPTFLUX (VT hash eb0687daed29f3651c61b0a2aa4a0cdcf2049a1ebae2e15e2dd9326471d318a1) calls the Gemini API at runtime to mutate its own source code on demand, enabling polymorphic evasion of static signature engines. HONESTCUE (VT collection malware--77a0b844-02bb-563c-b8fd-304f93e11ef1) likewise queries Gemini to generate fresh VBScript obfuscation and evasion routines per execution. CANFAIL (VT collection malware--30f26e32-0393-5023-92ef-f677f1def61c) and LONGSTREAM (VT collection malware--6cae6e39-72de-5b9e-aebe-47243e3dc63a) — both attributed to suspected Russia-nexus actors targeting Ukrainian organizations — embed AI-generated benign-looking decoy logic, with LONGSTREAM samples containing 32+ repeated daylight-saving-time queries and other inert administrative tasks specifically intended to dilute analyst attention and frustrate behavioral analytics; LLM-authored developer comments in CANFAIL explicitly annotate the inert padding. PROMPTSPY (Android), previously documented by ESET, now features a GeminiAutomationAgent module that calls generativelanguage.googleapis.com with the gemini-2.5-flash-lite model to autonomously navigate device UI. The agent serializes the live Android Accessibility-API view hierarchy into XML, supplies a benign-persona hardcoded prompt designed to defeat safety filters, and returns structured JSON CLICK/SWIPE actions with precise spatial coordinates derived by the model from in-prompt geometric reasoning; complementary modules implement reverse-TCP tunneling, FCM-based relaunch, dynamic VNC-relay and Gemini API key updates, biometric-replay attacks, and an AppProtectionDetector that draws an invisible overlay over the system uninstall button.
Five nation-state and uncategorized clusters are profiled. APT27 (PRC) used Gemini to accelerate development of a fleet-management application underpinning an ORB (operational relay box) network supporting MOBILE_WIFI and ROUTER device types, 4G/5G SIM-card residential-IP rotation, and a maxHops=3 multi-hop proxy topology. APT45 (DPRK) issued thousands of repetitive prompts to recursively analyze CVEs and validate PoC exploits, and is observed using OpenClaw and OneClaw agentic frameworks plus disposable vulnerable test environments. UNC2814 (PRC) leveraged expert-persona prompting (senior security auditor / C/C++ binary security expert) against TP-Link router firmware and Odette File Transfer Protocol implementations seeking pre-auth RCE primitives. UNC5673 (PRC; overlap with TEMP.Hex) targets South and Southeast Asian governments and operates obfuscated LLM-access middleware including Claude-Relay-Service and CLIProxyAPI for account pooling across Gemini, Claude, and OpenAI. UNC6201 (PRC) operationalized a GitHub-hosted Python script automating account registration, CAPTCHA bypass, SMS verification, and immediate cancellation to industrialize free/trial premium-LLM access. Cyber-crime cluster TeamPCP (UNC6780), in late March 2026, compromised maintainer accounts and pushed malicious pull requests into the Trivy, Checkmarx, LiteLLM, and BerriAI GitHub repositories, deploying the SANDCLOCK credential stealer to harvest AWS keys and GitHub tokens from victim build environments — the LiteLLM compromise is particularly impactful because the package functions as a multi-provider AI gateway and the stolen API secrets enable downstream access to victim AI systems, with TeamPCP partnering with ransomware and data-extortion crews for monetization.
Finally, Operation Overload, an ongoing pro-Russia information operation, has incorporated AI voice cloning to impersonate real journalists in fabricated video montages spliced with legitimate news footage, distributed across both digital platforms and printed posters, with secondary observed AI-IO activity attributed to actors in Iran, China, and Saudi Arabia. Across all clusters, the tracker emphasizes a structural shift: threat actors are professionalizing access to premium-tier AI through middleware, automated registration pipelines, and account aggregation — the productization of LLM abuse as a service layer underneath traditional cyber operations.
MITRE ATT&CK techniques used in TL-2026-0495
Defense Evasion
T1027 Obfuscated Files or Information; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1552 Unsecured Credentials
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing
Discovery
T1082 System Information Discovery; T1518 Software Discovery
Collection
Impact
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Reconnaissance
T1591 Gather Victim Org Information; T1592 Gather Victim Host Information
defense-impairment
Affected products and versions in GTIG AI Threat Tracker (May 2026)
- Unnamed open-source vendor (withheld by GTIG) — Web-based system administration tool
Vulnerable versions: pre-disclosure builds with hardcoded 2FA-bypass condition
Fixed in: pending vendor patch - TP-Link — Router firmware (research target of UNC2814 expert-persona prompting)
Vulnerable versions: multiple firmware images extracted for offline audit - Odette — Odette File Transfer Protocol (OFTP) implementations (UNC2814 research target)
Vulnerable versions: various - Aqua Security — Trivy vulnerability scanner (TeamPCP supply-chain compromise)
Vulnerable versions: versions distributed during late March 2026 compromise window
Fixed in: releases post-incident - Checkmarx — Checkmarx tooling (TeamPCP supply-chain compromise)
Vulnerable versions: compromise-window artifacts
Fixed in: post-incident - BerriAI — LiteLLM (AI gateway) and BerriAI repos (TeamPCP supply-chain compromise)
Vulnerable versions: compromise-window artifacts
Fixed in: post-incident - Google — Android (PROMPTSPY targets Accessibility Service / Gemini API client paths)
Vulnerable versions: devices without Play Protect enabled or with sideloaded malicious APKs
Fixed in: devices with Play Protect enabled receive detection
Remediation for GTIG AI Threat Tracker (May 2026)
Patches
- Apply vendor patch for the 2FA-bypass open-source web admin tool once published (vendor anonymized in GTIG report; monitor your stack's advisories)
- Upgrade Trivy, Checkmarx, LiteLLM, and BerriAI to releases post-dating the TeamPCP supply-chain compromise
Immediate actions
- Inventory and patch all internet-exposed open-source web-based system administration tools; require strong 2FA and disable any hardcoded bypass conditions identified in vendor advisories
- Block and alert on outbound calls from non-AI workloads to generativelanguage.googleapis.com (Gemini API) — investigate any endpoint making such calls without a documented business case
- Hunt for the PROMPTFLUX hash eb0687daed29f3651c61b0a2aa4a0cdcf2049a1ebae2e15e2dd9326471d318a1 and pull all IOCs from the VirusTotal collections for HONESTCUE, CANFAIL, and LONGSTREAM
- On mobile fleets, ensure Google Play Protect is enabled, block sideloading where policy permits, and hunt for Android packages requesting Accessibility Service together with network access to generativelanguage.googleapis.com
- Audit GitHub and PyPI dependencies for Trivy, Checkmarx, LiteLLM, and BerriAI; rotate any AWS keys and GitHub tokens that traversed CI/CD pipelines during late March 2026
- Rotate any LiteLLM-managed AI provider API keys and audit access logs for anomalous inference activity
Workarounds
- Where the 2FA-bypass tool cannot be immediately patched, restrict its administrative interface to a trusted management VLAN or VPN, and disable any local-bypass paths
- Pin AI gateway and dependency versions to known-good commits until vendor remediation is verified
- Block known LLM-relay middleware domains (Claude-Relay-Service, CLIProxyAPI infrastructure) at the egress perimeter on non-research networks
Longer-term hardening
- Deploy egress controls and DNS-layer policy that allow LLM API endpoints only from sanctioned AI workloads
- Adopt the Google Secure AI Framework (SAIF) and CoSAI guidance for governing internal LLM usage
- Implement static and dynamic build-pipeline integrity (signed commits, protected branches, two-person review, ephemeral build runners, secret-less CI)
- Stand up an AI-abuse detection capability that monitors for LLM-API beaconing patterns, prompt-injection telemetry, and autonomous-agent UI manipulation on managed endpoints
- Train SOC analysts to recognize AI-authored decoy code (repeated benign administrative loops, inert padding, LLM-style comments) so behavioral analytics are not diluted
- Subscribe to GTIG AI Threat Tracker and Mandiant feeds for ongoing AI-malware family disclosures
Weaknesses (CWE) in GTIG AI Threat Tracker (May 2026)
CWE-287, CWE-307, CWE-798, CWE-840, CWE-506, CWE-1357
Timeline of GTIG AI Threat Tracker (May 2026)
- GTIG publishes prior AI threat report establishing baseline of state-sponsored LLM abuse activity.
- VirusTotal reports security risks in the OpenClaw skill ecosystem, foreshadowing agentic-framework abuse documented in this tracker.
- TeamPCP (UNC6780) compromises Trivy, Checkmarx, LiteLLM, and BerriAI GitHub repositories via malicious pull requests, deploying SANDCLOCK credential stealer to harvest AWS keys and GitHub tokens from victim build environments.
- GTIG identifies an AI-developed Python exploit script bypassing 2FA on an open-source web administration tool, attributable to a prominent cyber-crime threat actor preparing for mass exploitation.
- GTIG begins responsible disclosure with the affected (anonymized) vendor while operating to disrupt the actor's mass-exploitation preparation.
- Google disables malicious Gemini/LLM-abuse accounts associated with PROMPTSPY and other AI-enabled malware operations; mass-exploitation event for the 2FA-bypass exploit foiled before kickoff.
- PROMPTFLUX, HONESTCUE, CANFAIL, and LONGSTREAM IOCs staged in dedicated VirusTotal collections for community hunting.
- BleepingComputer and additional security press amplify the GTIG findings, accelerating cross-industry hunting and patch prioritization.
- Google Threat Intelligence Group publishes the Q2 2026 AI Threat Tracker, the first authoritative confirmation of a threat-actor-deployed AI-developed zero-day exploit and a detailed enumeration of AI-enabled malware families and AI-augmented nation-state operations.
- As of 2026-05-29, this remains a live concern: the AI 2FA-bypass zero-day was disrupted and patched pre-exploitation, but the AI-enabled malware (PROMPTFLUX/PROMPTSPY) TTPs and nation-state LLM abuse persist, and the TeamPCP/UNC6780 supply-chain campaign is escalating (Cisco code theft, ~3,800 GitHub repos exfiltrated May 20). No arrests or takedowns reported.
Sources cited for GTIG AI Threat Tracker (May 2026)
- GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
- Google: Hackers used AI to develop zero-day exploit for web admin tool
- VirusTotal — PROMPTFLUX sample
- VirusTotal Collection — HONESTCUE malware
- VirusTotal Collection — CANFAIL malware (Russia-nexus, Ukraine targeting)
- VirusTotal Collection — LONGSTREAM malware (Russia-nexus, Ukraine targeting)
- MITRE ATLAS — Adversarial Threat Landscape for AI Systems
- Google Secure AI Framework (SAIF)
- Coalition for Secure AI (CoSAI)
Threats related to GTIG AI Threat Tracker (May 2026)
- TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks
- TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem Attack (CVE-2026-33634)
- Trivy Supply Chain Compromise — TeamPCP Credential-Stealing Malware Injected into CI/CD Pipelines (CVE-2026-33634)
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload
- LiteLLM Supply Chain Compromise — TeamPCP Multi-Ecosystem Campaign via Trojanized PyPI Packages
- Checkmarx Jenkins AST Plugin Supply Chain Compromise — TeamPCP Backdoored Plugin on Jenkins Marketplace
Detection coverage for TL-2026-0495
As of 2026-05-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0495 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.