
Cybercriminals are turning AI’s safety guardrails against it
Attackers are hiding malicious code behind biological and nuclear weapon schematics to prevent AI-powered security scanners from inspecting it, according to Google Threat Intelligence. The latest findings show cybercriminals increasingly using autonomous AI systems to target software supply chains and enterprise AI infrastructure.
Cybercriminals are weaponizing AI models’ own ethical guardrails to cloak their adversarial code. The findings were detailed in Google Threat Intelligence Group’s (GTIG) AI Threat Tracker report for Q3 2026, which revealed that cybercrime group UNC6780 pasted biological and nuclear weapon schematics directly into their malware's code comments, so that their reviewing security scanners would not inspect it.
Following the release of the group’s May 2026 report detailing adversarial misuse of AI, this latest report by GTIG, which is based on findings from Q2 2026, details a significant evolution in adversarial AI. The report highlights that threat actors are now deploying autonomous systems, explicitly targeting enterprise AI infrastructure, to scale their operations.
Key findings from the Q2 2026 observations include:
Software Supply Chain Vulnerabilities: While the widespread adoption of AI-assisted coding tools has accelerated development cycles, it has also seen the enterprise attack surface increase. Threat actors are deliberately targeting developers and LLM security scanners, with groups like UNC6780 infiltrating popular open-source platforms to plant hidden malware into the everyday tools developers rely on.
Targeting Proprietary AI IP: Enterprise AI infrastructure is now a primary target for corporate espionage and extortion. GTIG observed state-aligned and financially motivated groups are systematically exfiltrating proprietary models, source code, and internal research across the healthcare, government, and media sectors for corporate espionage and data theft extortion. Adversaries are also executing massive model distillation attacks via hidden proxy networks.
The Transition to Agentic AI: Attackers are moving away from manual operations and deploying multi-agent AI frameworks. These autonomous systems can manage vulnerability scanning pipelines, troubleshoot operational errors, and execute vast credential harvesting campaigns without human oversight.
Lifecycle Augmentation: State-sponsored and cybercrime groups, including those tied to China, Iran, North Korea, and Russia, are utilizing AI as a force multiplier across every phase of an attack.
Compute Hijacking and “LLMJacking”: To bypass the costs of premium model access, adversaries are acquiring stolen developer credentials on underground marketplaces. They’re leveraging these compromised accounts to hijack enterprise cloud infrastructure, effectively getting corporate environments to host and fund their illegal activities.
Overall, the report shows an environment where cybercriminals are weaponizing AI across the entire attack lifecycle, while sometimes even offloading their compute costs onto hijacked corporate infrastructure. Enterprise AI assets are prime targets for extortion, while the time window defenders have to intervene before an attack scales is rapidly shrinking.














