State-sponsored hackers are systematically exploiting Google’s Gemini AI model throughout every phase of cyberattacks, from initial reconnaissance through post-compromise operations, according to a new assessment from Google’s Threat Intelligence Group (GTIG).
The report reveals that advanced persistent threat (APT) groups from China, Iran, North Korea, and Russia are leveraging the large language model to enhance their offensive capabilities, while cybercriminals are increasingly integrating AI tools into their malicious operations.
The findings mark a significant evolution in how sophisticated adversaries are weaponizing publicly available AI systems. Rather than developing proprietary tools from scratch, these groups are effectively outsourcing portions of their attack development to commercial AI platforms, accelerating their operations while reducing costs and technical barriers.
How Threat Actors Are Weaponizing Gemini AI
Although GTIG noted that no APT or information operations actors have achieved breakthrough capabilities that fundamentally alter the existing threat landscape, the developments represent a concerning trend.
In one particularly alarming finding, threat actors have deployed more than 100,000 prompts against Gemini in large-scale model extraction attempts designed to replicate its reasoning capabilities across multiple languages.
Google’s investigation reveals that Chinese threat actors, including APT31 and Temp.HEX, have used expert cybersecurity personas to direct Gemini in automating vulnerability analysis and generating targeted testing plans within fabricated scenarios. In one documented case, a China-based actor tested Hexstrike MCP tooling while directing the model to analyze Remote Code Execution (RCE) techniques, web application firewall (WAF) bypass methods, and SQL injection test results against specific U.S.-based targets.
Another Chinese threat group frequently leveraged Gemini for code debugging, technical research, and guidance on intrusion capabilities.
The Iranian adversary APT42 deployed Google’s language model to enhance social engineering campaigns and accelerate the development of custom malicious tools through debugging, code generation, and exploitation technique research.
North Korean and Russian actors similarly incorporated Gemini into their operational workflows for tasks ranging from target profiling and open-source intelligence gathering to phishing lure creation, translation, coding assistance, and vulnerability testing.
Beyond state-sponsored groups, cybercriminals are also demonstrating increased sophistication in AI integration. Two malware families highlight this trend: HonestCue, a proof-of-concept framework discovered in late 2025, uses the Gemini API to dynamically generate C# code for second-stage malware payloads, which are then compiled and executed in memory. CoinBait, a React single-page application disguised as a cryptocurrency exchange, contains artifacts indicating its development was accelerated using AI code generation tools—potentially including the Lovable AI platform, based on client library usage patterns.




