From Advisor to Agent: Inside the Accelerating Arc of Adversary AI
Download resourcesAbout this session
A speaker who self-describes as leading Google's threat-intelligence work, citing Mandiant incident-response cases and Google Threat Intelligence Group research, argues that attackers have moved from using AI as an advisor for routine tasks toward deploying it as an autonomous agent across the attack lifecycle. The talk covers three fronts. In the software supply chain, AI-assisted coding has exploded the volume of unreviewed open-source code, letting a group called TeamPCP compromise package maintainers, self-propagate through stolen credentials across dozens of packages within hours, and hide malware inside AI-themed CI/CD jobs, including a fake bio-weapon instructions block designed to trip an automated LLM scanner so the malware underneath goes unexamined. Stolen GitHub tokens and cloud access are used to spin up GPUs and run large language models at the victim's expense, sometimes generating six-figure compute bills within hours, alongside a growing underground market for stolen AI accounts. State-linked espionage actors and extortionists alike also steal proprietary models and research to blackmail victims. The talk closes on guardrails, multi-model verification, and monitoring compute spikes as a detection signal.
Adversarial use of AI has transitioned from using models as mere 'advisors' for basic
productivity gains to more complex operations driven by automation and autonomous agents.
Grounded in Mandiant frontline incident response engagements and Google Threat
Intelligence Group (GTIG) research, this talk examines how threat actors are leveraging AI to
increase the speed, scale, and sophistication of their attacks.
Attendees will gain insights into key threat landscape developments:
● The Rise of Agentic Workflows: How adversaries are deploying autonomous
frameworks to orchestrate vulnerability scanning, exploitation, and mass credential
harvesting with minimal human intervention.
● Targeting the AI Supply Chain: How actors like TeamPCP compromise open-source
ecosystems enabling the mass theft of credentials and keys for AI tools, alongside a
look at rising underground market demand for stolen AI accounts and API keys.
● Enterprise Infrastructure Hijacking (LLMjacking): The trend of compromising cloud
environments to deploy LLM infrastructure and steal enterprise compute resources.
● The Hunt for Proprietary AI: How state-sponsored actors and extortion groups are
increasingly targeting organizations to steal proprietary models, data, and research.
To stay ahead of these maturing capabilities, this session equips attendees with the frontline
intelligence needed to anticipate, detect, and disrupt these threats
Key takeaways
- Add automated pre-deploy scanning for exposed secrets, tokens and malicious packages; AI coding assistants pull unreviewed open-source dependencies at a volume no manual review process can keep up with.
- Do not trust a single LLM to triage suspicious code: pair security-specific models, large reasoning models and static controls, since a single scanner's refusal on a fake weapons-instructions block can let the malware hidden behind it go unexamined.
- Treat GitHub tokens, cloud credentials and AI API keys as high-value targets; stolen access is already being used to spin up GPUs and run LLM workloads at the victim's expense, generating large compute bills within hours.
- Watch for anomalous cloud compute spikes as a detection signal for AI-infrastructure hijacking, not just for insider mistakes or misconfiguration.
- Inventory and protect proprietary models, prompts and research the same way you protect source code and customer data; both state-linked espionage actors and financially motivated extortionists are targeting them for theft and blackmail.
Speakers

Kimberly Goody is a Senior Manager with Google Threat Intelligence Group where she has led various teams focused on intelligence analysis and production. She brings over a decade of experience primarily focused on research into complex cybercrime… Read moreRead less
Kimberly Goody is a Senior Manager with Google Threat Intelligence Group where she has led various teams focused on intelligence analysis and production. She brings over a decade of experience primarily focused on research into complex cybercrime operations dating back to her time at NCFTA where she worked as a liaison between law enforcement and some of the world's largest financial institutions. She holds a master’s degree in security and intelligence studies and has also taught a graduate level course on cyber crime at Georgetown University.

