Google to Iran: Yes, we see you using Gemini for phishing and scripting. We're onto you
ID: 4fce6037-e842-501b-a0d9-51a62c7f5fb8
STIX ID: report--4fce6037-e842-501b-a0d9-51a62c7f5fb8
Feed Name: The Register (Security)
Google's Threat Intelligence Group reports that state-backed actors from Iran, China, North Korea and Russia have been using the Gemini LLM for reconnaissance, tailoring phishing and influence content, translations, and basic tooling; Iran accounted for roughly 75% of observed activity with specific APTs like APT42 heavily using the service. While operators attempted jailbreaks and requested code or abuse techniques, Google says its guardrails blocked malicious code generation and sensitive queries, and it continues to improve defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
