Rogue Agent Watch › Records › gtig-ai-developed-zero-day-2fa-bypass
GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
In its May 2026 AI Threat Tracker, Google Threat Intelligence Group (GTIG) reported what it calls its first identified case of a threat actor using a zero-day exploit that GTIG believes was developed with AI. The exploit targeted a popular open-source, web-based system administration tool and was held by a criminal threat actor that GTIG says was partnering with a prominent cybercrime actor to plan a mass exploitation operation. GTIG assesses with high confidence that an AI model was used in discovery and weaponization, basing that on indirect indicators in the exploit code rather than direct evidence of the tool, and states it does not believe Gemini was used. No model, actor name, victim, country or CVE is given. GTIG worked with the unnamed vendor on responsible disclosure and states its counter-discovery "may have prevented" the planned mass exploitation.
Impact as stated
No confirmed victims. GTIG states its counter-discovery and vendor disclosure may have prevented a planned mass exploitation event.
Facts as stated by sources
- Actor
- Unknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor (Cybercriminal)
- Category
- AI-orchestrated campaign
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Tool-assisted
- Guardrail bypass
- Unknown
- Attack lifecycle phases
- Resource development
- Target sectors
- Technology
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- GTIG coordinated responsible disclosure with the affected vendor before the planned mass exploitation occurred.
- GTIG recommends defensive use of AI for vulnerability discovery and remediation, secure-AI practices under its Secure AI Framework, and industry collaboration.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API
- PROMPTFLUX — experimental self-modifying malware abusing the Gemini API
Sources (1)
- GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
Google Threat Intelligence Group · Vendor report · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "gtig-ai-developed-zero-day-2fa-bypass". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/gtig-ai-developed-zero-day-2fa-bypass.json — CC BY-SA 4.0.