Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support
ID: d5c7ee0d-7afe-5ede-848b-989f441164da
STIX ID: report--d5c7ee0d-7afe-5ede-848b-989f441164da
Feed Name: The Hacker News
Google Threat Intelligence observed North Korea-linked UNC2970 and multiple other state and criminal actors leveraging the Gemini generative AI model for target profiling, tailored phishing persona creation, and to generate malicious code; researchers identified HONESTCUE (a Gemini-driven downloader that requests C# code from the API and compiles/executes it in memory) and COINBAIT (an AI-built credential-harvesting phishing kit), along with widespread model-extraction and AI-hosted malware delivery campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
