資料來源#
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
- GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
機構介紹#
Google 的威脅情報組織,追蹤政府支持的行為者、零日漏洞利用、協同資訊行動及重大網路犯罪,並與 Mandiant 的事件應變及 Managed Threat Defense 業務合作。其 AI 報告以定期發布的 AI Threat Tracker 系列為主:2026 年 2 月的報告探討蒸餾與對抗性實驗(NSA/CISA/FBI 的公告 AA26-251A 引用此報告,參見 Illicit Distillation);2026 年 5 月的報告探討 AI 漏洞利用及初始存取;而 2026 年第二季版則是 From Prompting to Autonomy(GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI,2026-09-08)。目前只有 9 月版已納入資料庫。
為何對這個 wiki 重要#
這是與 Anthropic 2026 年 9 月威脅報告並列、第二個直接來自第一方的對抗性 AI 使用觀察角度。兩份報告相隔兩天發布,彼此都未引用對方。兩者相符之處,是 agent-security 領域最有力的交叉佐證:AI 憑證市場(被竊模型存取權的經濟體系)、自主性光譜(Autonomous Intrusion)、影響力行動並無重大突破的結論(AI-Enabled Influence Operations),以及工業規模的蒸餾(Illicit Distillation)。它有兩個觀察角度與 Anthropic 不同:
- Mandiant 事件應變團隊能看到受害者一方。 Anthropic 的報告幾乎全是從自家平台內部觀察到的情況。GTIG 的案例包括在受害者環境內重建的入侵事件:LLMjacking 的完整流程、UNC6780 將行動交接給帶有 LAPSUS 品牌的勒索行為者,以及竊取資料勒索專有 AI 模型。這也解釋了為何其各行為者表格涵蓋 Gemini 以外的模型。第 9 和第 10 表的標題寫著 「misuse of Gemini」,但內容描述的是使用自訂 MCP 工具的 Claude Code(UNC6240 / ShinyHunters),以及 DeepSeek-Coder 和 Claude CLI hooks(MIDNIGHT NEPTUNE),所以標題只是範本,內容則來自更廣泛的遙測資料。應把標題視為有誤,並以表格內容作為證據。
- 跨供應商確認同一行為者。 Anthropic 記錄了 ShinyHunters 關聯人士在 Claude 上建立憑證管道;GTIG 則記錄 UNC6240(ShinyHunters)使用 Claude Code 撰寫混淆程式碼,並解析外洩目錄以進行勒索。兩家供應商描述的是同一個團隊使用第三方模型行動。
哪些內容應審慎看待#
整份報告都是 case-study,屬於第一方資料,且由作者自行評估:所有受阻止的行動都是 Google 自行處理的,文章沒有提供任何 IOC,所有數據也都來自 Google。文章最後轉為產品宣傳:Google AI Threat Defense(結合 Gemini、Wiz、CodeMender 及 Mandiant 情報),以及被稱為 「我們最強大的網路安全模型」 的 Gemini 3.8 Flash Cyber。這些都是 vendor-claim 陳述,本文沒有任何內容能衡量其效能。報告也將一項法律上的首例當作事實陳述:2026 年 6 月針對中國釣魚工具包服務 「Outsider Enterprise」 採取的行動,是 「Google 首次因濫用 Gemini 而提起法律行動」。文章有一處內部矛盾:Recon 儀表板的機密數量(參見被竊模型存取權的經濟體系)。
相關連結#
- 被竊模型存取權的經濟體系 — 提供第一個價格訊號(2026 年地下 AI 帳戶價格增加逾一倍)、資訊竊取程式竊取程式碼助理設定檔,以及 Mandiant 的 LLMjacking 完整流程
- Agent Supply Chain Risk — 記錄 UNC6780 / TeamPCP 與 DUSTMAKER:遭植入木馬的 MCP 伺服器、通過認證但含惡意內容的套件,以及針對 LLM 安全掃描器的拒絕誘餌提示
- Autonomous Intrusion — 記錄由代理程式建構、歷時六小時的資料蒐集行動及 Recon framework,並劃定「尚未完全自主」的界線
- Illicit Distillation — 從受害者角度記錄針對 Gemini、涉及超過 1 億次提示的抽取行動
- Google DeepMind — GTIG 表示這個姊妹組織會將其調查結果納入 Gemini 的分類器及模型層級拒絕機制
- Anthropic — 另一家直接發布第一方威脅報告的機構;兩份報告彼此佐證,但都無法驗證對方的內容
資料來源#
- GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI — GTIG AI Threat Tracker: From Prompting to Autonomy,Google Cloud 部落格,2026-09-08(顯示日期為 09-09),
case-study - China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — 將 GTIG 2026 年 2 月的蒸餾報告列入參考資料
Cited by 8
- Agent Supply Chain Risk×2
The Zenity campaign above went after the skill layer. GTIG's Q2 2026 tracker (gtig ai threat…
- AI-Enabled Influence Operations×2
GTIG's Q2 2026 tracker (gtig ai threat tracker from prompting to autonomy, case-study, first-party,…
- AI-Enabled State Surveillance×2
Google Threat Intelligence Group — the second provider's account: UNC5792's AI-classified Telegram…
- Autonomous Intrusion×2
Google Threat Intelligence Group — the second vendor's account: the six-hour agent-built harvesting…
- The Stolen Model-Access Economy×2
Google Threat Intelligence Group — the second vendor account, with the price trend, the config-file…
- Illicit Distillation
Google Threat Intelligence Group — the second victim's account: 100M+-prompt campaigns, multimodal…
- LLM-Driven Vulnerability Research
GTIG's Q2 2026 tracker (gtig ai threat tracker from prompting to autonomy, case-study, first-party)…
- Entities — People, Orgs, Tools & Projects
Google Threat Intelligence Group — Google's threat-intelligence unit (with Mandiant incident…
Related articles
- Anthropic
AI safety company / vendor of Claude; mission-as-tiebreaker culture; ~30–40 PMs across teams; Mike Krieger leads Labs r…
- Safeguard Evasion by Task Decomposition
Safeguards evaluate requests; adversaries run programs. Anthropic's September 2026 threat report reaches the same findi…
- AI-Accelerated Offense
Frontier models compress the vulnerability-to-exploit timeline from months to hours at marginal dollar cost; both attac…
- The Stolen Model-Access Economy
AI credentials have become loot, compute and cover at once — resale value, attack workloads run at the victim's expense…
- Autonomous Intrusion
The class of attack in which a model or a collective of agents conducts a network intrusion end-to-end — the campaign r…
