logo

Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support

ID: d5c7ee0d-7afe-5ede-848b-989f441164da

STIX ID: report--d5c7ee0d-7afe-5ede-848b-989f441164da

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Google Threat Intelligence observed North Korea-linked UNC2970 and multiple other state and criminal actors leveraging the Gemini generative AI model for target profiling, tailored phishing persona creation, and to generate malicious code; researchers identified HONESTCUE (a Gemini-driven downloader that requests C# code from the API and compiles/executes it in memory) and COINBAIT (an AI-built credential-harvesting phishing kit), along with widespread model-extraction and AI-hosted malware delivery campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.