GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented Operations

GTIG AI Threat Tracker (May 2026) (TL-2026-0495), also tracked as GTIG AI Threat Tracker May 2026, is a high-severity advanced persistent threat campaign, first published 2026-05-11. It is attributed to APT27 (China, North Korea, Russia) with high confidence, affects Unnamed open-source vendor (withheld by GTIG) Web-based system, maps to 28 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-0495

Threat ID
TL-2026-0495
Also known as
GTIG AI Threat Tracker May 2026, Mandiant AI Threat Tracker Q2 2026, First AI-Developed Zero-Day, AI Vulnerability Exploitation Initial Access report
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-05-11
Last reviewed
2026-05-11
Attribution
APT27
Attribution confidence
HIGH
Nation-state nexus
China, North Korea, Russia
Motivation
ESPIONAGE
Target sectors
government, defense, technology, telecommunications, financial services, media, software supply chain, cloud / AI service providers, managed service providers, research
Target regions
South Asia, Southeast Asia, Ukraine, Europe, North America, East Asia, Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in GTIG AI Threat Tracker (May 2026)

Malware and tooling: CANFAIL, HONESTCUE, LONGSTREAM, PROMPTFLUX, PROMPTSPY, SANDCLOCK, CLIProxyAPI, Claude-Relay-Service, Hexstrike, ORB network (operational relay box) with maxHops=3, OneClaw, OpenClaw

Google Threat Intelligence Group's May 11, 2026 AI Threat Tracker documents the first identified threat-actor use of an AI-developed zero-day exploit — a Python script that bypassed two-factor authentication on an unnamed open-source web-based system administration tool via a semantic logic flaw, planned for mass exploitation by a criminal actor and disrupted by GTIG. The report also enumerates five AI-enabled malware families (PROMPTFLUX dynamic source-code mutation, HONESTCUE VBScript just-in-time evasion, CANFAIL/LONGSTREAM Russia-nexus AI-generated decoy code targeting Ukraine, and the PROMPTSPY Android backdoor's GeminiAutomationAgent autonomous UI-driving module), AI-augmented operations by PRC-nexus APT27/UNC2814/UNC5673/UNC6201 and DPRK-nexus APT45 (including expert-persona jailbreaking, recursive PoC validation, ORB fleet-management development, and obfuscated LLM-access middleware), TeamPCP (UNC6780) supply-chain compromises of Trivy/Checkmarx/LiteLLM/BerriAI deploying SANDCLOCK credential stealer, and Operation Overload's pro-Russia AI voice-cloning IO campaign.

How GTIG AI Threat Tracker (May 2026) works

On May 11, 2026, Google Threat Intelligence Group (GTIG) published its Q2 2026 AI Threat Tracker, the first authoritative confirmation that a threat actor has weaponized a zero-day vulnerability developed with the assistance of a large language model. The exploit — a Python script bypassing two-factor authentication on a popular, intentionally unnamed open-source web-based system administration tool — targeted a semantic logic flaw in which a developer hardcoded a trust assumption that contradicted the application's own 2FA enforcement logic. Such high-level reasoning bugs are precisely the class of flaw modern frontier LLMs excel at surfacing and which traditional static-analysis and fuzzing tooling consistently misses. The script bore unmistakable AI authorship markers: an abundance of educational docstrings, a hallucinated CVSS score in inline comments, textbook Pythonic structure characteristic of LLM training-data style, detailed help menus, and a clean ANSI color class implementation. A prominent cyber-crime threat actor was preparing a mass-exploitation campaign against vulnerable internet-exposed instances; GTIG independently discovered the script, disrupted operator infrastructure, and pursued responsible disclosure with the affected vendor. Google explicitly ruled out Gemini as the originating LLM but did not name the specific model used.

The tracker further documents five AI-enabled malware families. PROMPTFLUX (VT hash eb0687daed29f3651c61b0a2aa4a0cdcf2049a1ebae2e15e2dd9326471d318a1) calls the Gemini API at runtime to mutate its own source code on demand, enabling polymorphic evasion of static signature engines. HONESTCUE (VT collection malware--77a0b844-02bb-563c-b8fd-304f93e11ef1) likewise queries Gemini to generate fresh VBScript obfuscation and evasion routines per execution. CANFAIL (VT collection malware--30f26e32-0393-5023-92ef-f677f1def61c) and LONGSTREAM (VT collection malware--6cae6e39-72de-5b9e-aebe-47243e3dc63a) — both attributed to suspected Russia-nexus actors targeting Ukrainian organizations — embed AI-generated benign-looking decoy logic, with LONGSTREAM samples containing 32+ repeated daylight-saving-time queries and other inert administrative tasks specifically intended to dilute analyst attention and frustrate behavioral analytics; LLM-authored developer comments in CANFAIL explicitly annotate the inert padding. PROMPTSPY (Android), previously documented by ESET, now features a GeminiAutomationAgent module that calls generativelanguage.googleapis.com with the gemini-2.5-flash-lite model to autonomously navigate device UI. The agent serializes the live Android Accessibility-API view hierarchy into XML, supplies a benign-persona hardcoded prompt designed to defeat safety filters, and returns structured JSON CLICK/SWIPE actions with precise spatial coordinates derived by the model from in-prompt geometric reasoning; complementary modules implement reverse-TCP tunneling, FCM-based relaunch, dynamic VNC-relay and Gemini API key updates, biometric-replay attacks, and an AppProtectionDetector that draws an invisible overlay over the system uninstall button.

Five nation-state and uncategorized clusters are profiled. APT27 (PRC) used Gemini to accelerate development of a fleet-management application underpinning an ORB (operational relay box) network supporting MOBILE_WIFI and ROUTER device types, 4G/5G SIM-card residential-IP rotation, and a maxHops=3 multi-hop proxy topology. APT45 (DPRK) issued thousands of repetitive prompts to recursively analyze CVEs and validate PoC exploits, and is observed using OpenClaw and OneClaw agentic frameworks plus disposable vulnerable test environments. UNC2814 (PRC) leveraged expert-persona prompting (senior security auditor / C/C++ binary security expert) against TP-Link router firmware and Odette File Transfer Protocol implementations seeking pre-auth RCE primitives. UNC5673 (PRC; overlap with TEMP.Hex) targets South and Southeast Asian governments and operates obfuscated LLM-access middleware including Claude-Relay-Service and CLIProxyAPI for account pooling across Gemini, Claude, and OpenAI. UNC6201 (PRC) operationalized a GitHub-hosted Python script automating account registration, CAPTCHA bypass, SMS verification, and immediate cancellation to industrialize free/trial premium-LLM access. Cyber-crime cluster TeamPCP (UNC6780), in late March 2026, compromised maintainer accounts and pushed malicious pull requests into the Trivy, Checkmarx, LiteLLM, and BerriAI GitHub repositories, deploying the SANDCLOCK credential stealer to harvest AWS keys and GitHub tokens from victim build environments — the LiteLLM compromise is particularly impactful because the package functions as a multi-provider AI gateway and the stolen API secrets enable downstream access to victim AI systems, with TeamPCP partnering with ransomware and data-extortion crews for monetization.

Finally, Operation Overload, an ongoing pro-Russia information operation, has incorporated AI voice cloning to impersonate real journalists in fabricated video montages spliced with legitimate news footage, distributed across both digital platforms and printed posters, with secondary observed AI-IO activity attributed to actors in Iran, China, and Saudi Arabia. Across all clusters, the tracker emphasizes a structural shift: threat actors are professionalizing access to premium-tier AI through middleware, automated registration pipelines, and account aggregation — the productization of LLM abuse as a service layer underneath traditional cyber operations.

MITRE ATT&CK techniques used in TL-2026-0495

Defense Evasion

T1027 Obfuscated Files or Information; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1552 Unsecured Credentials

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

Discovery

T1082 System Information Discovery; T1518 Software Discovery

Collection

T1113 Screen Capture

Impact

T1531 Account Access Removal

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Reconnaissance

T1591 Gather Victim Org Information; T1592 Gather Victim Host Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in GTIG AI Threat Tracker (May 2026)

  • Unnamed open-source vendor (withheld by GTIG) — Web-based system administration tool
    Vulnerable versions: pre-disclosure builds with hardcoded 2FA-bypass condition
    Fixed in: pending vendor patch
  • TP-Link — Router firmware (research target of UNC2814 expert-persona prompting)
    Vulnerable versions: multiple firmware images extracted for offline audit
  • Odette — Odette File Transfer Protocol (OFTP) implementations (UNC2814 research target)
    Vulnerable versions: various
  • Aqua Security — Trivy vulnerability scanner (TeamPCP supply-chain compromise)
    Vulnerable versions: versions distributed during late March 2026 compromise window
    Fixed in: releases post-incident
  • Checkmarx — Checkmarx tooling (TeamPCP supply-chain compromise)
    Vulnerable versions: compromise-window artifacts
    Fixed in: post-incident
  • BerriAI — LiteLLM (AI gateway) and BerriAI repos (TeamPCP supply-chain compromise)
    Vulnerable versions: compromise-window artifacts
    Fixed in: post-incident
  • Google — Android (PROMPTSPY targets Accessibility Service / Gemini API client paths)
    Vulnerable versions: devices without Play Protect enabled or with sideloaded malicious APKs
    Fixed in: devices with Play Protect enabled receive detection

Remediation for GTIG AI Threat Tracker (May 2026)

Patches

  • Apply vendor patch for the 2FA-bypass open-source web admin tool once published (vendor anonymized in GTIG report; monitor your stack's advisories)
  • Upgrade Trivy, Checkmarx, LiteLLM, and BerriAI to releases post-dating the TeamPCP supply-chain compromise

Immediate actions

  • Inventory and patch all internet-exposed open-source web-based system administration tools; require strong 2FA and disable any hardcoded bypass conditions identified in vendor advisories
  • Block and alert on outbound calls from non-AI workloads to generativelanguage.googleapis.com (Gemini API) — investigate any endpoint making such calls without a documented business case
  • Hunt for the PROMPTFLUX hash eb0687daed29f3651c61b0a2aa4a0cdcf2049a1ebae2e15e2dd9326471d318a1 and pull all IOCs from the VirusTotal collections for HONESTCUE, CANFAIL, and LONGSTREAM
  • On mobile fleets, ensure Google Play Protect is enabled, block sideloading where policy permits, and hunt for Android packages requesting Accessibility Service together with network access to generativelanguage.googleapis.com
  • Audit GitHub and PyPI dependencies for Trivy, Checkmarx, LiteLLM, and BerriAI; rotate any AWS keys and GitHub tokens that traversed CI/CD pipelines during late March 2026
  • Rotate any LiteLLM-managed AI provider API keys and audit access logs for anomalous inference activity

Workarounds

  • Where the 2FA-bypass tool cannot be immediately patched, restrict its administrative interface to a trusted management VLAN or VPN, and disable any local-bypass paths
  • Pin AI gateway and dependency versions to known-good commits until vendor remediation is verified
  • Block known LLM-relay middleware domains (Claude-Relay-Service, CLIProxyAPI infrastructure) at the egress perimeter on non-research networks

Longer-term hardening

  • Deploy egress controls and DNS-layer policy that allow LLM API endpoints only from sanctioned AI workloads
  • Adopt the Google Secure AI Framework (SAIF) and CoSAI guidance for governing internal LLM usage
  • Implement static and dynamic build-pipeline integrity (signed commits, protected branches, two-person review, ephemeral build runners, secret-less CI)
  • Stand up an AI-abuse detection capability that monitors for LLM-API beaconing patterns, prompt-injection telemetry, and autonomous-agent UI manipulation on managed endpoints
  • Train SOC analysts to recognize AI-authored decoy code (repeated benign administrative loops, inert padding, LLM-style comments) so behavioral analytics are not diluted
  • Subscribe to GTIG AI Threat Tracker and Mandiant feeds for ongoing AI-malware family disclosures

Weaknesses (CWE) in GTIG AI Threat Tracker (May 2026)

CWE-287, CWE-307, CWE-798, CWE-840, CWE-506, CWE-1357

Timeline of GTIG AI Threat Tracker (May 2026)

  • GTIG publishes prior AI threat report establishing baseline of state-sponsored LLM abuse activity.
  • VirusTotal reports security risks in the OpenClaw skill ecosystem, foreshadowing agentic-framework abuse documented in this tracker.
  • TeamPCP (UNC6780) compromises Trivy, Checkmarx, LiteLLM, and BerriAI GitHub repositories via malicious pull requests, deploying SANDCLOCK credential stealer to harvest AWS keys and GitHub tokens from victim build environments.
  • GTIG identifies an AI-developed Python exploit script bypassing 2FA on an open-source web administration tool, attributable to a prominent cyber-crime threat actor preparing for mass exploitation.
  • GTIG begins responsible disclosure with the affected (anonymized) vendor while operating to disrupt the actor's mass-exploitation preparation.
  • Google disables malicious Gemini/LLM-abuse accounts associated with PROMPTSPY and other AI-enabled malware operations; mass-exploitation event for the 2FA-bypass exploit foiled before kickoff.
  • PROMPTFLUX, HONESTCUE, CANFAIL, and LONGSTREAM IOCs staged in dedicated VirusTotal collections for community hunting.
  • BleepingComputer and additional security press amplify the GTIG findings, accelerating cross-industry hunting and patch prioritization.
  • Google Threat Intelligence Group publishes the Q2 2026 AI Threat Tracker, the first authoritative confirmation of a threat-actor-deployed AI-developed zero-day exploit and a detailed enumeration of AI-enabled malware families and AI-augmented nation-state operations.
  • As of 2026-05-29, this remains a live concern: the AI 2FA-bypass zero-day was disrupted and patched pre-exploitation, but the AI-enabled malware (PROMPTFLUX/PROMPTSPY) TTPs and nation-state LLM abuse persist, and the TeamPCP/UNC6780 supply-chain campaign is escalating (Cisco code theft, ~3,800 GitHub repos exfiltrated May 20). No arrests or takedowns reported.

Sources cited for GTIG AI Threat Tracker (May 2026)

Threats related to GTIG AI Threat Tracker (May 2026)

Detection coverage for TL-2026-0495

As of 2026-05-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0495 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats