logo

Google says hackers are abusing Gemini AI for all attacks stages

ID: 4aa112d8-ca79-5b0d-8cef-07bdbf65c24a

STIX ID: report--4aa112d8-ca79-5b0d-8cef-07bdbf65c24a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Google Threat Intelligence Group reports that state-sponsored and criminal threat actors are leveraging the Gemini LLM to support all attack stages — from OSINT and tailored phishing lure creation to vulnerability testing, code generation, C2 development, and data exfiltration; observed misuse includes APT-linked activity (multiple nation-state groups), AI-assisted malware frameworks (HonestCue, CoinBait) and ClickFix-delivered macOS infostealers (AMOS), plus large-scale model extraction attempts, prompting Google to disable abusive accounts and harden defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.