From Prediction to Pattern: Google's AI Threat Tracker Validates the Case for Agent Trust Infrastructure

Two months ago we warned that the GTG-1002 incident was a harbinger. Google just confirmed it.
Tim Williams — CEO and Cofounder — AstraSync AI
In December 2025, we published The Infrastructure Gap (https://papers.ssrn.com/abstract=5928236), a paper analysing the Anthropic GTG-1002 incident and arguing that the agentic economy required fundamentally new trust infrastructure. We made a specific prediction: that we would see incidents making GTG-1002 look minor in comparison, and that the timeline would compress faster than anyone expected.
Two months later, Google’s Threat Intelligence Group has confirmed that prediction in detail.
What Just Happened
On 12 February 2026, GTIG released their latest AI Threat Tracker report, produced in collaboration with Google DeepMind ahead of the Munich Security Conference. The findings document a systematic pattern of state-sponsored AI weaponisation that goes well beyond what we saw with GTG-1002.
The GTG-1002 incident involved a single Chinese state actor using a single AI platform (Claude Code) to orchestrate attacks against approximately thirty organisations. The GTIG report documents multiple state-backed groups from China, Iran, North Korea, and Russia, all independently converging on the same approach. Not one threat actor, one platform. Multiple threat actors, multiple platforms, multiple attack methodologies.
Here is what GTIG found.
China’s APT31 used structured prompts to direct Gemini into automated vulnerability analysis against US-based targets. They tested Hexstrike, a red-team framework that operates through the Model Context Protocol (MCP), to automate reconnaissance and penetration testing. GTIG noted that this activity “explicitly blurs the line between a routine security assessment query and a targeted malicious reconnaissance operation.”
Iran’s APT42 leveraged Gemini for reconnaissance and targeted social engineering, crafting realistic personas to engage targets, building scraping tools, and researching vulnerability exploits.
North Korea’s UNC2970 used Gemini to synthesise open-source intelligence and profile high-value targets at cybersecurity and defence companies.
Russia’s APT28 incorporated Gemini into operational workflows spanning target profiling, phishing lure creation, translation, and vulnerability testing.
This is no longer a single-platform curiosity. This is a documented, multi-nation pattern.
The New Threat Vectors
Several elements of the GTIG report describe capabilities that go meaningfully beyond what GTG-1002 demonstrated. These deserve specific attention.
AI embedded in the weapon itself. GTIG identified a malware family called HONESTCUE that appeared in September 2025. HONESTCUE uses Gemini’s API to dynamically generate C# code for second-stage payloads, then compiles and executes those payloads in memory. This is a meaningful escalation. The GTG-1002 incident involved humans using an AI platform to plan and execute attacks. HONESTCUE makes the AI platform a runtime component of the malware itself. The AI is not the attacker’s assistant. It is embedded in the weapon.
This distinction matters because it represents a new class of threat that traditional cybersecurity defences are not designed to detect. File-based detection misses code compiled in memory. Signature-based analysis cannot match payloads that are generated fresh by an LLM for each execution. The malware is polymorphic by design.
MCP as an attack vector. APT31’s use of Hexstrike MCP tooling is particularly significant for anyone building or deploying agentic systems. MCP is the same protocol layer that legitimate agentic commerce and agent-to-agent interaction frameworks are being built on. Google’s own A2A protocol, Stripe’s Agent Commerce Protocol, and numerous enterprise integration patterns all rely on MCP or comparable mechanisms. The attack surface is no longer theoretical. State actors are already weaponising the same protocol infrastructure the industry is building its agentic future on.
Stolen API keys powering offensive toolkits. GTIG identified Xanthorox, a dark-web toolkit marketed as a bespoke offensive AI platform. Investigation revealed it was actually powered by commercial AI products, including Gemini, accessed through stolen API keys. This directly validates a central argument in The Infrastructure Gap: credential-based authentication fails catastrophically when credentials are stolen. We cited the August 2025 Drift AI breach where stolen OAuth tokens compromised over 700 organisations. The Xanthorox case extends the same pattern to AI API keys specifically.
Model extraction at scale. GTIG documented a campaign involving over 100,000 automated prompts attempting to replicate Gemini’s reasoning capabilities through knowledge distillation. While this is primarily an intellectual property concern for model providers, it introduces a question the agent identity community has not yet addressed: if an agent’s capabilities can be systematically cloned through querying, what does that mean for identity verification of the agent itself?
What This Means for Agent Infrastructure
When we published The Infrastructure Gap, we argued that the agentic economy required a new category of trust infrastructure combining verified identity chains, dynamic trust scoring, immutable audit trails, and externally enforced operational constraints. We structured that argument around the GTG-1002 incident because it was the clearest available proof point.
The GTIG report provides several additional proof points, each reinforcing different elements of that argument.
The absence of verified accountability chains is being actively exploited. Every attack documented in the GTIG report exploits the same structural gap. APT31 used fabricated expert personas. APT42 crafted synthetic identities for social engineering. Xanthorox operated through stolen credentials. In every case, the target system had no mechanism to verify who was behind the agent, who was instructing it, or what it was authorised to do. The five-party trust chain model we proposed in The Infrastructure Gap (Developer, Owner, Agent, Instructor, Counterparty) addresses precisely this gap. Verified identity at every link means fabricated personas fail at the first challenge.
Constraints implemented within an agent’s runtime remain insufficient. HONESTCUE demonstrates the structural limitation we identified as “the guardrail illusion.” The malware operates by sending prompts to Gemini’s API and executing the generated code in a context the malware author controls. No amount of model-level guardrails prevents this because the adversary controls the execution environment. As we argued in The Infrastructure Gap, the only reliable enforcement is externalising constraints to counterparties who can verify and enforce them independently of the agent’s runtime state. The PDLSS framework (Purpose, Duration, Limit, Scope, Self-instantiation) we proposed records constraints immutably at registration, making them verifiable by any system the agent attempts to interact with and unmodifiable by the agent or its operator at runtime.
Detection requires continuous monitoring, not periodic audits. The GTIG report describes patterns of activity that would be detectable through systematic behavioural analysis. APT31’s structured prompts follow recognisable patterns. HONESTCUE’s API calls to Gemini create observable network traffic. The challenge is that detection requires continuous monitoring against established baselines, not static rule matching or post-incident review. Dynamic trust scoring that updates in real time based on observed behaviour is a necessary component of any infrastructure designed to govern agentic systems at scale.
Reactive enforcement does not protect targets. Google disabled accounts linked to malicious activity after the fact. This is the reactive pattern The Infrastructure Gap identified as structurally insufficient for the agentic economy. Disabling accounts after an attack campaign has concluded does not protect the organisations that were targeted during it. It does not prevent the same techniques from being replicated through different accounts. Infrastructure that enables counterparties to verify and constrain agent behaviour before granting access is the only approach that addresses the problem at the point of interaction.
Where the Threat Picture Has Expanded
It is important to distinguish between threat vectors that agent identity infrastructure directly addresses and those that require complementary approaches.
The trust chain failures, credential theft, and absence of counterparty verification documented across APT31, APT42, UNC2970, and Xanthorox all fall squarely within the scope of agent identity and trust infrastructure. These are the scenarios The Infrastructure Gap was designed to address: agents operating across organisational boundaries without verified identity, enforceable constraints, or immutable audit trails.
The HONESTCUE malware case represents something distinct. Here, a commercial AI platform is being used as a runtime component within traditional malware, with the malicious actor controlling the execution environment entirely. The AI is not operating as an autonomous agent through declared channels. It is being called as an API within a hostile process. This is closer to traditional endpoint security than agent governance. The API provider can detect and block abuse patterns (as Google has done), and endpoint security products can detect the execution behaviour, but agent identity infrastructure operates at a different layer.
This distinction matters because overextending the scope of any single solution erodes its credibility. Agent identity infrastructure addresses the structural gaps in how autonomous systems authenticate, constrain, and audit their interactions across trust boundaries. It does not replace endpoint detection, API abuse monitoring, or model-level safety measures. It complements them by providing the identity and constraint layer those systems can query and enforce against.
The GTIG report makes the case that both categories of threat are accelerating simultaneously. Addressing them requires coordinated infrastructure across multiple layers, not a single solution claiming universal coverage.
The Timeline is Compressing
The most important takeaway from the GTIG report is the rate of convergence. Four nation-states independently arrived at the same conclusion: commercial AI platforms are force multipliers for offensive operations. They are integrating these tools across the full attack lifecycle, from reconnaissance through to data exfiltration. The sophistication is increasing. The barriers to entry are decreasing.
When we published The Infrastructure Gap in December 2025, we posed a question: “How many more breaches will it take before we prioritise the solution?”
Two months later, the evidence base has expanded from one documented incident to a systematic pattern involving multiple nation-states, multiple platforms, and genuinely novel attack techniques including AI-powered polymorphic malware and MCP-based autonomous reconnaissance.
The agentic economy is not a future state. It is being built right now, on the same protocol infrastructure that state actors are already weaponising. The infrastructure gap we identified is not closing. It is widening.
Agent identity and trust infrastructure is not a nice-to-have. It is the minimum viable governance requirement for an economy that runs on autonomous systems. The evidence for that position is no longer emerging. It has arrived.
Tim Williams is CEO and Co-Founder of AstraSync AI, which provides agent identity and trust infrastructure for the agentic economy. AstraSync’s commercial interests should be considered when evaluating the analysis above.
The Infrastructure Gap: Why Platform Security Cannot Protect Against Agentic Attacks is available at https://papers.ssrn.com/abstract=5928236.
The GTIG AI Threat Tracker report was released on 12 February 2026 ahead of the Munich Security Conference.
Further reading on AstraSync
This essay first appeared on Medium on 14 February 2026.

