Threat Groups Aren’t Developing New Attack Vectors with GenAI: RSAC Presentation
ID: 73321b4e-93d5-5792-a853-f6a761ef039e
STIX ID: report--73321b4e-93d5-5792-a853-f6a761ef039e
Feed Name: The Cyber Express
At RSAC 2025 Google Threat Intelligence reported that nation-state APTs—particularly actors linked to Iran, China and North Korea—are leveraging Gemini GenAI to enhance reconnaissance, vulnerability research, malware scripting (including sandbox/VM evasion), and phishing campaign development; the presentation characterized these uses as efficiency improvements to existing TTPs rather than the emergence of new AI-native attack vectors, and also noted defensive GenAI applications for vulnerability detection and malware analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
