HomeSecurityGoogle: Hackers exploit Gemini AI for all stages of attacks

Google: Hackers exploit Gemini AI for all stages of attacks

State-backed hackers are using Google’s Gemini AI model to support all stages of an attack, from reconnaissance to post-breach actions. Malicious actors from China (APT31, Temp.HEX), Iran (APT42), North Korea (UNC2970), and Russia have used Gemini for target profiling and open source intelligence, phishing bait creation, text translation, coding, vulnerability testing, and troubleshooting.

See also: When does Apple plan to unveil the new Siri with Gemini

Gemini AI

Cybercriminals are also showing increased interest in AI tools and services that could aid in illicit activities, such as ClickFix campaigns. Google’s Threat Intelligence Group (GTIG) notes in a report that APT adversaries are using Gemini to support their campaigns “from identifying and crafting phishing baits to deploying command and control (C2) and extracting data.” The Chinese hackers used a cybersecurity expert to ask Gemini to automate vulnerability analysis and provide targeted test plans within a constructed scenario.

In one case, a China-based threat actor constructed a scenario testing the Hexstrike MCP and directed the model to analyze remote code execution (RCE) techniques, WAF bypass techniques, and SQL injection test results against specific U.S.-based targets. Another China-based actor frequently used Gemini to patch their code, conduct research, and advise on technical capabilities for attacks.

Iranian APT42 exploited Google’s LLM for social engineering campaigns, using it as a development platform to accelerate the creation of custom malicious tools, including debugging, code generation, and research into exploit techniques. Malicious use by other threat actors to implement new capabilities into existing malware families has also been observed, including the CoinBait phishing kit and the HonestCue downloader and launcher malware

See also: Google Gemini Vulnerability: Private Calendar Data Exposure

Google: Hackers exploit Gemini AI for all stages of attacks

GTIG says there have been no major breakthroughs in this regard, though the tech giant expects malware operators to continue to incorporate AI capabilities into their tools. HonestCue is a proof-of-concept malware framework spotted in late 2025 that uses Gemini’s API to generate C# code for second-stage malware, then compiles and executes the payloads in memory.

CoinBait is a phishing kit wrapped in a React SPA that pretends to be a cryptocurrency exchange to collect credentials.

It contains artifacts that indicate that its development proceeded using AI code generation tools. One indicator of LLM usage is log messages in the malware’s source code that are preceded by “ Analytics:, ” which could help defenders track data extraction processes. Based on the malware samples, GTIG researchers believe that the malware was created using the Lovable AI platform, as the developer used the Lovable Supabase client and lovable.app .

Cybercriminals also used genetic AI services in ClickFix campaigns, delivering the AMOS for macOS. Users were lured into executing malicious commands through ads that appeared in search results for queries related to troubleshooting specific problems.

The report further notes that Gemini has faced attempts at AI model extraction and distillation, with organizations leveraging authorized API access to systematically query the system and replicate decision-making processes to replicate its functionality.

See also: What we can expect from the new Siri with Gemini

Google: Hackers exploit Gemini AI for all stages of attacks

While the problem does not pose a direct threat to the users of these models or their data, it is a significant commercial, competitive, and intellectual property problem for the creators of these models.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS