Google says hackers are abusing Gemini AI for all attacks stages
ID: 4aa112d8-ca79-5b0d-8cef-07bdbf65c24a
STIX ID: report--4aa112d8-ca79-5b0d-8cef-07bdbf65c24a
Feed Name: Bleeping Computer
Google Threat Intelligence Group reports that state-sponsored and criminal threat actors are leveraging the Gemini LLM to support all attack stages — from OSINT and tailored phishing lure creation to vulnerability testing, code generation, C2 development, and data exfiltration; observed misuse includes APT-linked activity (multiple nation-state groups), AI-assisted malware frameworks (HonestCue, CoinBait) and ClickFix-delivered macOS infostealers (AMOS), plus large-scale model extraction attempts, prompting Google to disable abusive accounts and harden defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
