GTIG AI Threat Tracker (May 2026)
report · report:gtig-ai-threat-tracker-may-2026
Google Threat Intelligence Group AI Threat Tracker (May 2026), first AI-generated zero-day exploit ITW; AI-augmented malware (CANFAIL, LONGSTREAM, PROMPTFLUX, HONESTCUE); state-actor Gemini abuse (UNC2814, APT45, APT27, UNC5673)
Defender insights
What each entry about GTIG AI Threat Tracker (May 2026) tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (7 across 5 tactics)
7 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- StealthObfuscated Files or Information
- Defense ImpairmentSubvert Trust Controls
- Credential AccessUnsecured Credentials · Unsecured Credentials: Credentials In Files
- Command and ControlApplication Layer Protocol · Application Layer Protocol: Web Protocols
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
Defense Impairment TA0112
T1553Subvert Trust Controls×1
Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗
Entries about GTIG AI Threat Tracker (May 2026) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- attack.mitre.org5 (42%)
- cloud.google.com2 (17%)
- cert.ssi.gouv.fr1 (8%)
- helpnetsecurity.com1 (8%)
- securityweek.com1 (8%)
- thehackernews.com1 (8%)
- theregister.com1 (8%)
All cited sources (12)
- attack.mitre.orgT1027 Obfuscated Files or Informationhttps://attack.mitre.org/techniques/T1027/
- attack.mitre.orgT1071.001 Application Layer Protocol: Web Protocolshttps://attack.mitre.org/techniques/T1071/001/
- attack.mitre.orgT1190 Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- attack.mitre.orgT1552.001 Credentials In Fileshttps://attack.mitre.org/techniques/T1552/001/
- attack.mitre.orgT1553 Subvert Trust Controlshttps://attack.mitre.org/techniques/T1553/
- cert.ssi.gouv.frCERTFR-2026-ACT-016 agentic-AI advisoryhttps://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-016/
- cloud.google.comoriginal Adversarial Misuse of Generative AI reporthttps://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai
- cloud.google.comGoogle Cloud Threat Intelligence, AI vulnerability exploitation initial access, 2026-05-11https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access
- helpnetsecurity.comHelp Net Security, 2026-05-11https://www.helpnetsecurity.com/2026/05/11/google-ai-vulnerability-exploitation/
- securityweek.comSecurityWeek, 2026-05-11https://www.securityweek.com/google-detects-first-ai-generated-zero-day-exploit/
- thehackernews.comThe Hacker News, 2026-05-11https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html
- theregister.comThe Register, 2026-05-11https://www.theregister.com/ai-ml/2026/05/11/google-says-criminals-used-ai-built-zero-day-in-planned-mass-hack-spree/5237982