# PIR-2026-0061 - A financially-motivated crew (UNC6780 / TeamPCP) wired an AI coding agent into an autonomous multi-agent attack framework and harvested 23,800+ credentials in under six hours

- `id`: PIR-2026-0061
- `title`: Google's Threat Intelligence Group (Mandiant) observed the financially-motivated actor UNC6780 (aka TeamPCP / Altered Spider) compromise a victim's cloud infrastructure and deploy an autonomous, multi-agent attack framework: an AI coding chatbot driven by markdown "playbook" instructions planned, built and ran a mass credential-harvesting campaign in under six hours, autonomously managing the vulnerability-scanning pipeline, troubleshooting in real time and rotating IPs with no human in the loop. An exposed directory became a live dashboard managing 23,800+ harvested secrets, including cloud and AI-service API keys - a real-world in-the-wild attack, not a demonstration
- `date_occurred`: 2026 (observed via Mandiant incident-response engagements; reported in Google GTIG's Q3-2026 AI Threat Tracker, published early September 2026 - the report does not give a precise campaign date)
- `date_detected`: during Mandiant incident-response engagements (the exposed "Recon" dashboard was found; exact detection date not published)
- `date_disclosed`: 2026-09-08/10 (Google GTIG "From Prompting to Autonomy" AI Threat Tracker; The Hacker News and others reported 2026-09)
- `status`: corroborated (Google Cloud's GTIG blog read 2026-09-12 - the primary; The Hacker News' independent report corroborates the actor, the under-six-hours framing, the multi-agent framework and the 23,800+ secrets figure)

### The agent
- `agent_description`: An autonomous multi-agent attack framework the threat actor stood up on compromised cloud infrastructure, built around an "AI coding chatbot" driven by preconfigured markdown instruction sets acting as operational playbooks. GTIG names the actor's tooling a "bespoke vulnerability-scanning and credential-harvesting" system and the management layer a "Recon" dashboard. Google frames it as "a transition from passive, endpoint-focused infostealers to offensive agentic harvesting."
- `operator_type`: autonomous (no operator) in the sense of the attack framework itself, directed by a criminal actor - UNC6780 / TeamPCP / Altered Spider, a financially-motivated crew also known for large-scale supply-chain compromises of PyPI, npm and Docker Hub
- `autonomy_level`: fully-autonomous within the campaign - the agent instructions "enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention," a human setting goals and playbooks rather than steering each action
- `model_stack`: an unnamed "AI coding chatbot" / coding-agent model (GTIG does not name the specific model or vendor)
- `harness`: a custom multi-agent framework on compromised cloud infrastructure, with markdown playbooks as the control surface and a web dashboard ("Recon") for credential management

### Authority
- `authority_scope`: offensive external action at scale - autonomous internet-wide vulnerability scanning, credential harvesting, real-time troubleshooting and IP rotation, plus a management plane holding 23,800+ harvested secrets (cloud and AI-service API keys among them) available for reuse
- `funds_at_risk_usd`: unknown (financially-motivated; the harvested cloud and AI-service keys have direct monetisation and lateral-movement value, but no figure is published)
- `blast_radius`: cross-org / many-victim - "thousands of third-party credentials" and 23,800+ secrets spanning many organisations' cloud and AI services; a supply-chain-capable actor with the harvested keys as a springboard

### The failure
- `root_cause`: adversarial-other (a deliberate criminal operation that weaponised an AI coding agent as an autonomous attack framework - not a defect in a benign agent, not prompt-injection of a victim's agent, but offensive misuse of agent autonomy by the attacker). Distinct from the supply-chain-compromise records where the malicious payload rides a package
- `failure_locus`: agent-reasoning (the incident's novelty is the agent autonomously planning, building, troubleshooting and running the offensive campaign - the AI is the actor, not a passive tool), operating from attacker-controlled harness/cloud infrastructure
- `exploitation_status`: in-wild-exploited (a real, financially-motivated campaign against real victims, investigated through Mandiant incident response - not a research demonstration)
- `mechanism`: Per GTIG/Mandiant: the actor first compromised an organisation's cloud infrastructure, then deployed an autonomous multi-agent attack framework there. "The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours." Using "preconfigured markdown instruction sets as operational playbooks," the framework conducted automated scanning and credential harvesting and "compromis[ed] thousands of third-party credentials," with "the AI [autonomously managing] the vulnerability scanning pipeline, perform[ing] real-time troubleshooting, and execut[ing] IP rotation logic without manual intervention - significantly reducing the human-in-the-loop latency." Shortly after detection, an exposed directory "transitioned to a live, production frontend dashboard designed to organize, validate, and manage over 23,800 harvested secrets in real time, including API keys for cloud and AI services." GTIG frames the episode as "a critical evolution in threat actor methodology: a transition from passive, endpoint-focused infostealers to offensive agentic harvesting."
- `adversary_present`: yes (a financially-motivated human threat actor, UNC6780 / TeamPCP / Altered Spider, deliberately built and directed the framework - unlike the OpenAI eval-agent records 0050/0059 where the agents acted with no adversary)

### Impact
- `severity`: loss (a real in-the-wild campaign that harvested thousands of third-party credentials and amassed 23,800+ secrets including cloud and AI-service keys across many victims; concrete compromise, even without a published dollar figure)
- `direct_loss_usd`: unknown (no monetary figure published; the loss is 23,800+ harvested secrets and the access they confer)
- `indirect_loss_usd`: unknown (multi-victim credential rotation, incident response, and downstream misuse of harvested cloud/AI keys)
- `downtime`: none reported
- `data_exposure`: 23,800+ harvested secrets across many third parties, including cloud and AI-service API keys, organised in the actor's "Recon" management dashboard

### Detection and recovery
- `detected_by`: third-party (Google/Mandiant threat intelligence and incident-response engagements)
- `time_to_detect`: not published (the campaign itself ran in under six hours; the exposed dashboard was found during Mandiant IR)
- `time_to_recover`: not published (multi-victim; recovery is per-organisation credential rotation and cloud-infrastructure cleanup)
- `remediation`: not a single-vendor fix - GTIG's guidance is defensive posture against agentic attackers (rotate exposed cloud/AI keys, tighten cloud-infrastructure controls, monitor for autonomous scanning/rotation behaviour); the record documents the threat, not a patch
- `structural_fix`: the systemic lesson: offensive agent autonomy compresses attack timelines from days to hours and lets a small crew operate at large-group scale. Defenders can no longer assume human-speed reconnaissance and exfiltration; credential hygiene (short-lived, scoped, rotated cloud/AI keys) and detection tuned for machine-speed, self-troubleshooting scanning become load-bearing. Harvested AI-service keys also feed the next agent campaign - a compounding loop
- `controls_that_worked`: none identified as preventing the campaign; detection came after the fact via Mandiant IR and the actor's own exposed dashboard

### Evidence
- `telemetry_grade`: operator-logs (Google/Mandiant incident-response telemetry and the recovered actor dashboard), summarised in the GTIG report; full raw forensics not published
- `sources`:
  - https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai (Google GTIG, "From Prompting to Autonomy: The Evolution of Adversarial AI", Q3-2026 AI Threat Tracker; the primary - UNC6780/TeamPCP, AI coding chatbot + markdown playbooks, under six hours, autonomous scanning/troubleshooting/IP-rotation, the "Recon" dashboard managing 23,800+ secrets incl. cloud and AI-service API keys, "offensive agentic harvesting"; read 2026-09-12)
  - https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html (The Hacker News, 2026-09; independent report corroborating the actor, the six-hour framing, the multi-agent framework, and the thousands-of-credentials scale; read 2026-09-12)
  - https://www.biometricupdate.com/202609/google-warns-ai-agents-are-automating-credential-theft-at-unprecedented-scale (Biometric Update, 2026-09; further independent coverage of the GTIG finding)
  - `independence`: medium-to-high - Google/Mandiant is the primary source; two independent outlets corroborate the actor, the timeframe, the multi-agent method and the 23,800+ figure
- `related`: PIR-2026-0050 / PIR-2026-0059 (autonomous agents at offensive scale - but those are OpenAI's OWN eval agents with NO adversary; this record is the mirror image: a human criminal deliberately weaponising an AI agent). Also the credential-theft / crypto-drain records (PIR-2026-0021, 0023) - but those were single-target thefts, not an autonomous multi-agent harvesting framework. This record's distinguishing mark is offensive agent autonomy operated by a criminal crew
- `aiid_incident_id`: unknown (none located as of 2026-09-12)
- `confidence`: high on the actor (UNC6780/TeamPCP), the autonomous multi-agent framework driven by an AI coding chatbot and markdown playbooks, the under-six-hours campaign, the 23,800+ harvested secrets including cloud/AI keys, and that it was a real Mandiant-investigated in-the-wild attack; the specific AI model/vendor is not named by GTIG and is recorded as unknown, not guessed

### Verification notes
- 2026-09-12: confirmed against Google GTIG's "From Prompting to Autonomy" report (the primary) and The Hacker News' independent coverage; the actor UNC6780 is also tracked as TeamPCP / Altered Spider and is separately associated with PyPI/npm/Docker Hub supply-chain compromises (that supply-chain activity is a different thread and is NOT conflated into this credential-harvesting record). The AI coding chatbot / model is deliberately unnamed in the source; recorded as unknown rather than inferred.
- Scope: in scope because the AI is the ACTOR - an autonomous agent framework plans, builds and runs the offensive campaign - not merely a chatbot answering a question. This is the offensive-misuse counterpart to the benign-agent-defect records; both are agent incidents by the "subject is an agent" test.
