INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploys AI-Powered Phishing Tool for Widescale Credential Theft
| 2026-09-08 12:03 CRITICAL HIGH AI-ENABLED ATTACK PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Hackers have built AI frameworks for widescale credential theft, targeting countries in the TARGET_REGION. The attackers are believed to be China-linked cyberespionage actors, with other groups such as Russia-based UNC5792 also using AI models to automate monitoring bots searching Telegram channels for information of interest to their governments. These attacks affect multiple sectors, including government and public services, with a reported breach of Florida's "DAVID" DMV database attributed to the ShinyHunters hackers. The attackers use an AI-assisted, automated exploitation and post-exploitation pipeline to steal credentials, which is then used for widescale credential theft. As of now, no further information on the current status of these attacks has been reported.
Technical Mitigations AI-generated
• Patch Microsoft September 2026 Patch Tuesday fixes, specifically addressing the two zero-days.
• Detect and block ShinyHunters' use of fake shops to steal credit cards by monitoring MageCart traffic.
• Implement age-awareness APIs in Windows applications to detect if users are children, teens, or adults.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
bi•••••.toulas
ad•••••.com
ww•••••.com
de•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TeamPCPTeamPCPShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2016 August
Threat actors exploited vulnerabilities in August 2016 updates for Windows Server 2016 to trigger a specific error code, potentially leading to widescale credential theft.
Click on any entity below to view its context and source!
infrastructure
Windows
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
tactic
T1584.004 - Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
infrastructure
2016 Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
September 2026
Microsoft released a September 2026 Patch Tuesday that addressed 966 flaws, including two zero-days.
Click on any entity below to view its context and source!
organisation
Microsoft
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
966 flaws
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
2 days
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
September 8, 2026
Threat actors used an AI coding chatbot and markdown agent instructions to build, deploy, and execute a mass credential-harvesting campaign in under six hours.
Click on any entity below to view its context and source!
organisation
ThreatLocker
[Image 34: ThreatLocker](
* Home
* News
* Security
* Hackers build AI frameworks for widescale credential theft
# Hackers build AI frameworks for widescale credential theft
By
###### Bill Toulas
* September 8, 2026
* 08:03 AM
* 0
!
data_breach
0 September
[Image 34: ThreatLocker](
* Home
* News
* Security
* Hackers build AI frameworks for widescale credential theft
# Hackers build AI frameworks for widescale credential theft
By
###### Bill Toulas
* September 8, 2026
* 08:03 AM
* 0
!
infrastructure
Windows
This approach dramatically reduced “human-in-the-loop” latency and the response windows for defenders.
organisation
Google
In less than six hours, the threat actor planned, built, and deployed a mass credential-harvesting campaign using an AI coding chatbot, a prompt, and markdown agent instructions, Google says.
!
organisation
API
Its files included instructions for AI agents, knowledge files, and OpenClaw artifacts related to the framework that managed in real-time more than 23,800 harvested secrets, such as API keys.
!
threat_actor
TeamPCP
AI tool abuse has also been observed in supply-chain attacks conducted by UNC6780 (TeamPCP), Gemini AI distillation operations involving 100 million prompts, and a growing market for stolen AI account credentials and API keys.
organisation
Gemini AI
AI tool abuse has also been observed in supply-chain attacks conducted by UNC6780 (TeamPCP), Gemini AI distillation operations involving 100 million prompts, and a growing market for stolen AI account credentials and API keys.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
EU CRA
Check your EU CRA readiness in 5 questions.
2003 - 2026
Threat actors utilized the website's advertising and social media features to build AI frameworks for widescale credential theft.
Click on any entity below to view its context and source!
organisation
Social & Feeds
* Advertising
* Write for BleepingComputer
* Social & Feeds
* Changelog
Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure
Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved
[]( "Back to Top")
2026/09/08
Threat actors have integrated AI capabilities into multiple stages of an attack lifecycle, including reconnaissance, phishing, malware development, exploitation, post-exploitation, and data processing.
Click on any entity below to view its context and source!
organisation
Webinar
[Image 49: Webinar](
##### Follow us:
*
organisation
Recon
The Recon panel
**The Recon panel**
_Source: Google_
GTIG's report notes other examples where China-linked cyberespionage actors experimented "with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline."
infrastructure
Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
BigBear Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
MFA
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
victims
258 organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
CLI
Get the report
### Related Articles:
Google Gemini CLI abused as a hacking agent, malware botnet operator
JadePuffer ransomware used AI agent to automate entire attack
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
How Anthropic plans to watermark Claude's AI-generated text
Google says AI helped Chrome fix 1,072 security bugs in two releases
*
organisation
JadePuffer
Get the report
### Related Articles:
Google Gemini CLI abused as a hacking agent, malware botnet operator
JadePuffer ransomware used AI agent to automate entire attack
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
How Anthropic plans to watermark Claude's AI-generated text
Google says AI helped Chrome fix 1,072 security bugs in two releases
*
organisation
Claude
Get the report
### Related Articles:
Google Gemini CLI abused as a hacking agent, malware botnet operator
JadePuffer ransomware used AI agent to automate entire attack
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
How Anthropic plans to watermark Claude's AI-generated text
Google says AI helped Chrome fix 1,072 security bugs in two releases
*
organisation
Chrome
Get the report
### Related Articles:
Google Gemini CLI abused as a hacking agent, malware botnet operator
JadePuffer ransomware used AI agent to automate entire attack
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
How Anthropic plans to watermark Claude's AI-generated text
Google says AI helped Chrome fix 1,072 security bugs in two releases
*
infrastructure
Linux
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
infosec news
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
organisation
APM
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
Hackers
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
infrastructure
Windows
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
organisation
Stack Protection
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
organisation
Windows Registry
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
organisation
the Windows Registry
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
organisation
Magento
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
organisation
Adobe
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
threat_actor
ShinyHunters
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DMV
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DoppelCart
[Image 7: DoppelCart fraud network uses 119,000 fake shops to steal credit cards DoppelCart fraud network uses 119,000 fake shops to steal credit cards](
* !
organisation
IP
[Image 31: How to change IP address.jpg) How to change IP address](
* !
organisation
safely.jpg
Access the dark web safely.jpg)
organisation
LLM
“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG notes.
organisation
CTI
[Image 46: CTI Starter Kit + 2026 SANS CTI Survey CTI Starter Kit + 2026 SANS CTI Survey](
* !
organisation
Upcoming Webinar
[Image 40: ThreatLocker](
Upcoming Webinar
!
organisation
ClickFix
Blockchain Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain](
S ponsor Posts
* !
organisation
Freestar.com
Submitting...
SUBMIT
Freestar.com
!
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
Metrics
infrastructure
Microsoft 365
Affected Product
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
victims
258
Organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
infrastructure
Windows
Affected Product
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
This approach dramatically reduced “human-in-the-loop” latency and the response windows for defenders.
Metrics
infrastructure
2,016
Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
Metrics
data_breach
0
September
[Image 34: ThreatLocker](
* Home
* News
* Security
* Hackers build AI frameworks for widescale credential theft
# Hackers build AI frameworks for widescale credential theft
By
###### Bill Toulas
* September 8, 2026
* 08:03 AM
* 0
!
Intelligence Sources
BleepingComputer
2026-09-08
Hackers build AI frameworks for widescale credential theft
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:24
Comprehensive Tactical Telemetry
Highly Correlated Entities
33x
organisation
Identified Entity
Recon
entity
6x
tactic
Cyber Operation Type
Espionage
tactic
6x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
4x
timeline
Temporal Reference
September 8, 2026
date
4x
general metric
Video
1
video
3x
attribution
Attributing Entity
Telegram
authority
3x
infrastructure
Affected Product
Linux
software
2x
target region
Target Country
United States
country
2x
general metric
Windows
11
windows
2x
threat actor
APT Group
ShinyHunters
actor
Contextual Telemetry
Context Block
18 METRICS
source region
Origin Country
China
country
industry
Targeted Sector
Government
sector
general metric
Attack Rogue Ai Agents
700
attack rogue ai agents
general metric
Security Bugs
1,072
security bugs
general metric
Microsoft
365
microsoft
victims
Organizations
258
organizations
infrastructure
Windows Server
2,016
windows server
general metric
Flaws
966
flaws
general metric
Days
2
days
general metric
Fake Shops
119,000
fake shops
data breach
September
0
september
general metric
Harvested Secrets
23,800
harvested secrets
general metric
Prompts
100,000,000
prompts
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Hacked Sites
5,400
hacked sites
general metric
Questions
5
questions
general metric
%
37
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.