HomeSecurityGoogle: APT hacking groups use Gemini AI for attacks

Google: APT hacking groups use Gemini AI for attacks

More than 57 state-backed hacking groups (APTs) linked to China, Iran, North Korea, and Russia are using Google's artificial intelligence (AI) technology (Gemini) in their malicious operations and attacks.

APT Hacking groups AI Gemini

“ Attackers are experimenting with Gemini to power their operations. It enhances their productivity, but they are not yet using it to develop new capabilities ,” the Google Threat Intelligence Group (GTIG) said in a new report . “ Currently, they are primarily using AI for research, troubleshooting code, and creating and localizing content .”

Government-backed hacking groups, also known as Advanced Persistent Threat (APT) groups, have sought to use AI tools to enhance various stages of their attacks: coding and scripting tasks, payload development, intelligence gathering, researching publicly known vulnerabilities. AI systems have also been used for post-breach activities, such as evading protection measures.

See also: FunkSec: New “AI” ransomware with over 85 victims

Iranian APT hacking groups are the ones that are most abusing Google’s Gemini. The APT42 was behind 30% of Gemini usage in the country. It used its AI tools to create campaigns phishing and conduct reconnaissance. APT42 shares elements with groups monitored as Charming Kitten and Mint Sandstorm, and typically uses social engineering to infiltrate networks and cloud environments.

Chinese APT hacking groups use the Gemini AI tool to reconnoiter, troubleshoot code, and infiltrate victim networks through techniques such as lateral movement, privilege escalation, data extraction , and evasion.

Russian groups have primarily used Gemini to convert publicly available malware into another coding language and add layers of encryption to existing code.

Finally, North Korean hacking groups used Google’s AI service to research infrastructure and hosting providers. In addition, North Koreans used Gemini to write cover letters and research job openings (activities that would likely support North Korea’s efforts to place secret IT workers in Western companies).

See also: GenAI applications in cybersecurity

Gemini abuse efforts also revolve around local event research, content creation, and translation, as part of influence operations orchestrated by Iran, China, and Russia. In total, APT groups from more than 20 countries have used Gemini.

Google: APT hacking groups use Gemini AI for attacks

As AI technology continues to advance, it is expected that more threat actors will incorporate it into their operations, making the need for robust cybersecurity measures even more critical. It also highlights the need for increased collaboration and information sharing between governments, organizations, and researchers to stay ahead of emerging threats.

There are ongoing discussions about regulating the development and use of artificial intelligence to prevent harm and protect privacy. It is important for all stakeholders to carefully consider the implications of this technology and work towards responsible and ethical implementation.

See also: FBI warns of GenAI abuse

Cybersecurity professionals must adapt and develop AI-powered tools to more effectively detect and prevent attacks. This includes using machine learning algorithms to analyze large amounts of data and identify patterns that could indicate malicious activity. By harnessing the power of AI for defense, organizations can stay ahead of evolving threats and protect their systems and sensitive information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS