AI News

Nation-State Hackers Weaponize Google Gemini: A New Era of AI-Driven Cyber Threats

February 12, 2026 – In a significant revelation that underscores the double-edged nature of artificial intelligence, Google’s Threat Intelligence Group (GTIG) and Google DeepMind have released a comprehensive report detailing how nation-state adversaries are systematically integrating Google Gemini into their cyberattack lifecycles.

The report, released today ahead of the Munich Security Conference, highlights a disturbing trend: Advanced Persistent Threat (APT) groups from China, Iran, and North Korea have moved beyond mere experimentation. These actors are now actively employing Generative AI to accelerate reconnaissance, refine social engineering campaigns, and even dynamically generate malicious code during active operations.

The Operational Shift: From Experimentation to Integration

For the past year, the cybersecurity community has warned of the potential for Large Language Models (LLMs) to lower the barrier to entry for cybercriminals. However, Google’s latest findings confirm that sophisticated state-sponsored groups are leveraging these tools to enhance efficiency and evasion capabilities.

According to the report, the usage of Gemini by these groups is not monolithic. Different actors have adopted the technology to suit their specific strategic goals, ranging from deep-dive open-source intelligence (OSINT) gathering to the real-time translation of phishing lures.

John Hultquist, chief analyst at GTIG, noted that while North Korean and Iranian groups were early adopters of AI for social engineering, Chinese actors are now developing more complex, agentic use cases to streamline vulnerability research and code troubleshooting.

Threat Actor Profile: How Nations Are Exploiting AI

The report provides a granular look at how specific APT groups are utilizing Gemini. The following table summarizes the key actors and their observed methodologies:

Summary of Nation-State AI Exploitation

Threat Group Origin Primary Targets Key Misuse of Gemini
APT42 (Charming Kitten) Iran Education, Govt, NGOs Translating phishing lures, refining social engineering personas, and drafting persuasive emails.
UNC2970 North Korea Defense & Aerospace Synthesizing OSINT to profile high-value targets; impersonating corporate recruiters.
TEMP.Hex (Mustang Panda) China Govt & NGOs (Pakistan/Europe) Compiling structural data on separatist organizations and specific individuals.
APT31 (Zirconium) China US Industrial/Political Sectors Using "expert cybersecurity personas" to automate vulnerability analysis and testing plans.

Iran: Refining the Art of Deception

APT42, a group historically associated with the Iranian Islamic Revolutionary Guard Corps (IRGC), has heavily integrated Gemini into its social engineering operations. Known for targeting researchers, journalists, and activists, APT42 uses the model to translate content and polish the grammar of phishing emails, making them indistinguishable from legitimate correspondence.

By feeding Gemini biographies of targets, the group generates tailored pretexts—scenarios designed to build immediate trust. This capability allows them to bridge language gaps and cultural nuances that previously served as red flags for potential victims.

North Korea: Industrial-Scale Reconnaissance

For the North Korean group UNC2970, AI serves as a force multiplier for espionage. The group targets the defense and aerospace sectors, often posing as legitimate recruiters to deliver malware.

Google’s analysis reveals that UNC2970 uses Gemini to scrape and synthesize vast amounts of data from professional networking sites (such as LinkedIn). The AI helps them map out organizational hierarchies, identify key technical personnel, and draft hyper-realistic job descriptions used in spear-phishing campaigns.

China: Automated Vulnerability Research

Chinese state-sponsored actors, including TEMP.Hex and APT31, have demonstrated some of the most technical applications of the technology. These groups have been observed using Gemini to troubleshoot their own malware code and research publicly known vulnerabilities.

In one alarming instance, a Chinese group utilized Gemini to simulate "expert cybersecurity personas." These AI agents were tasked with automating the analysis of software vulnerabilities and generating testing plans to bypass security controls on US-based targets. This suggests a move toward automated offensive operations, where AI agents assist in the planning phase of an intrusion.

The Rise of AI-Native Malware: "Honestcue"

Perhaps the most technical revelation in the report is the discovery of Honestcue, a malware strain identified in September 2025. Unlike traditional malware that carries its malicious payload, Honestcue functions as a hollow shell that relies on the cloud.

Honestcue leverages the Google Gemini API to dynamically generate and execute malicious C# code in memory. By offloading the malicious logic to an AI response, the attackers achieve two goals:

  1. Obfuscation: Traditional antivirus tools that rely on static file analysis struggle to detect the threat because the malicious code does not exist until the AI generates it.
  2. Polymorphism: The code generated by the AI can vary slightly with each execution, complicating signature-based detection.

This "living off the land" approach—where the "land" is now a cloud-based AI service—represents a significant evolution in malware development.

The "Jailbreak" Ecosystem and Model Theft

Beyond nation-state espionage, the report sheds light on the growing underground economy of "Jailbreak-as-a-Service." Cybercriminals are marketing tools that claim to be custom, uncensored AI models but are often merely wrappers around commercial APIs like Gemini or OpenAI.

One such tool, Xanthorox, advertises itself as a private, self-hosted AI for generating ransomware and malware. Google’s investigation, however, revealed that Xanthorox simply routes prompts through jailbroken instances of legitimate models, stripping away safety filters to deliver malicious content.

Furthermore, financially motivated groups are increasingly conducting Model Extraction Attacks (MEAs). These "distillation attacks" involve systematically probing a mature model like Gemini to extract its training patterns, effectively stealing the intellectual property to train cheaper, smaller clone models. While this does not compromise user data, it poses a severe threat to the competitive advantage of AI developers.

Google’s Defense and the Path Forward

In response to these findings, Google has taken aggressive action, disabling all identified accounts and assets associated with the APT groups mentioned in the report. The company emphasized that while adversaries are using Gemini for content generation and coding assistance, there is no evidence that the security of the Gemini model itself has been compromised.

"For government-backed threat actors, LLMs have become essential tools for technical research, targeting, and the rapid generation of nuanced phishing lures," the report states.

Creati.ai notes that this development signals a permanent shift in the threat landscape. As AI models become more multimodal and agentic, the window between a vulnerability being discovered and exploited will continue to shrink. The integration of AI into offensive cyber operations is no longer a theoretical risk—it is the new standard of engagement.

For enterprise security teams, this necessitates a pivot toward behavior-based detection systems capable of identifying AI-generated anomalies, rather than relying solely on static indicators of compromise. As the arms race between AI-enabled attackers and AI-driven defenders accelerates, the integrity of the AI supply chain itself will likely become the next major battleground.

Featured
Flaq AI Media API
Flaq AI Media API
Flaq AI is a unified AI media API platform for generating images, videos, and LLM-powered workflows with stable models
AirMusic
AirMusic
AirMusic.ai generates high-quality AI music tracks from text prompts with style, mood customization, and stems export.
AdsCreator.com
AdsCreator.com
Generate polished, on‑brand ad creatives from any website URL instantly for Meta, Google, and Stories.
Atoms
Atoms
AI-driven platform that builds full‑stack apps and websites in minutes using multi‑agent automation, no coding required.
KiloClaw
KiloClaw
Hosted OpenClaw agent: one-click deploy, 500+ models, secure infrastructure, and automated agent management for teams and developers.
Refly.ai
Refly.ai
Refly.AI empowers non-technical creators to automate workflows using natural language and a visual canvas.
VoxDeck
VoxDeck
Next-gen AI presentation maker,Turn your ideas & docs into attention-grabbing slides with AI.
Skywork.ai
Skywork.ai
Skywork AI is an innovative tool to enhance productivity using AI.
Pippit
Pippit
Elevate your content creation with Pippit's powerful AI tools!
Qoder
Qoder
Qoder is an agentic coding platform for real software, Free to use the best model in preview.
BGRemover
BGRemover
Easily remove image backgrounds online with SharkFoto BGRemover.
FineVoice
FineVoice
Clone, Design, and Create Expressive AI Voices in Seconds, with Perfect Sound Effects and Music.
Flowith
Flowith
Flowith is a canvas-based agentic workspace which offers free 🍌Nano Banana Pro and other effective models...
Diagrimo
Diagrimo
Diagrimo transforms text into customizable AI-generated diagrams and visuals instantly.
Elser AI
Elser AI
All-in-one AI video creation studio that turns any text and images into full videos up to 30 minutes.
FixArt AI
FixArt AI
FixArt AI offers free, unrestricted AI tools for image and video generation without sign-up.
SuperMaker AI Video Generator
SuperMaker AI Video Generator
Create stunning videos, music, and images effortlessly with SuperMaker.
Funy AI
Funy AI
AI bikini & kiss videos from images or text. Try the AI Clothes Changer & Image Generator!
SharkFoto
SharkFoto
SharkFoto is an all-in-one AI-powered platform for creating and editing videos, images, and music efficiently.
AnimeShorts
AnimeShorts
Create stunning anime shorts effortlessly with cutting-edge AI technology.
AIsa
AIsa
AIsa gives AI agents one gateway to models, skills, APIs, and payments with OpenAI-compatible access.
Gemini Omni - Video Generator
Gemini Omni - Video Generator
AI video creation platform for conversational editing, multimodal references, and coherent short-form generation.
Scavio AI
Scavio AI
Real-time multi-platform search API that helps AI agents fetch structured web, shopping, video, and social data.
AdMakeAI
AdMakeAI
AI ad generator that creates high-performing static and UGC ads for brands in seconds.
CreateMemorial
CreateMemorial
CreateMemorial helps families build lasting online memorial websites and funeral slideshow videos to honor loved ones.
WriteHybrid AI Humanizer
WriteHybrid AI Humanizer
WriteHybrid is an AI humanizer and detector that rewrites text naturally while helping users bypass AI detection.
whatslove.ai
whatslove.ai
AI dating coach that customizes advice, conversation starters and date ideas tailored to your personality.
Seedance 2.0 Video AI
Seedance 2.0 Video AI
Generate cinematic 1080p videos from prompts, images, and reference clips with synchronized audio.
VidMage
VidMage
Realistic AI face swaps for photos, videos, and GIFs, instantly and effortlessly.
AI Clothes Changer by SharkFoto
AI Clothes Changer by SharkFoto
AI Clothes Changer by SharkFoto instantly lets you virtually try on outfits with realistic fit, texture, and lighting.
Mubert AI
Mubert AI
Mubert is an AI music platform that generates, extends, remixes, and vocalizes royalty-free tracks in seconds.
StitchPilot.ai
StitchPilot.ai
Browser-based AI embroidery tool for converting images, previewing stitch files, and inspecting machine formats.
SkyGen Plus
SkyGen Plus
A multi-model AI creation platform for generating images, videos, and music with one streamlined workflow.
AI Gift finder by wishwave
AI Gift finder by wishwave
AI gift finder that builds shareable wishlists from real products across hundreds of popular stores.
happy horse AI
happy horse AI
Open-source AI video generator that creates synchronized video and audio from text or images.
InstantChapters
InstantChapters
Create Youtube Chapters with one click and increase watch time and video SEO thanks to keyword optimized timestamps.
NerdyTips
NerdyTips
AI-powered football predictions platform delivering data-driven match tips across global leagues.
HappyHorseAIStudio
HappyHorseAIStudio
Browser-based AI video generator for text, images, references, and video editing.
EaseMate AI
EaseMate AI
All-in-one AI assistant for chat, writing, study help, image creation, and video generation in one browser-based platform.
UNI-1 AI
UNI-1 AI
UNI-1 is a unified image generation model combining visual reasoning with high-fidelity image synthesis.
Lyria3 AI
Lyria3 AI
AI music generator that creates high-fidelity, fully produced songs from text prompts, lyrics, and styles instantly.
Couple AI - AI Couple Photo Maker
Couple AI - AI Couple Photo Maker
Create realistic AI couple portraits from selfies with themed styles, fast generation, and private HD downloads.
AIToHuman
AIToHuman
Free AI text humanizer that rewrites AI-generated content into natural, human-like writing instantly.
insmelo AI Music Generator
insmelo AI Music Generator
AI-driven music generator that turns prompts, lyrics, or uploads into polished, royalty-free songs in about a minute.
Iara Chat
Iara Chat
Iara Chat: An AI-powered productivity and communication assistant.
BeatMV
BeatMV
Web-based AI platform that turns songs into cinematic music videos and creates music with AI.
MusicGPT
MusicGPT
AI music platform for generating songs, sound effects, vocals, and audio edits from simple prompts.
Tome AI PPT
Tome AI PPT
AI-powered presentation maker that generates, beautifies, and exports professional slide decks in minutes.
GPT Image 2 Online
GPT Image 2 Online
An AI image generator and editor with photorealistic results, accurate text rendering, and strong prompt following.
WhatsApp AI Sales
WhatsApp AI Sales
WABot is a WhatsApp AI sales copilot that delivers real-time scripts, translations, and intent detection.
Claude API
Claude API
Claude API for Everyone
Kirkify
Kirkify
Kirkify AI instantly creates viral face swap memes with signature neon-glitch aesthetics for meme creators.
Anijam AI
Anijam AI
Anijam is an AI-native animation platform that turns ideas into polished stories with agentic video creation.
Free GPT Image 2
Free GPT Image 2
A free GPT Image 2 generator for creating posters, ads, comics, and UI mockups with accurate typography.
Wan 2.7
Wan 2.7
Professional-grade AI video model with precise motion control and multi-view consistency.
Image3D - AI 2D to 3D Model Generator (GLB, OBJ, STL, PLY)
Image3D - AI 2D to 3D Model Generator (GLB, OBJ, STL, PLY)
Browser-based AI that turns any 2D image or text prompt into a 3D model in 30 seconds. Export GLB, OBJ, STL, PLY—free
Text to Music
Text to Music
Turn text or lyrics into full, studio-quality songs with AI-generated vocals, instruments, and multi-track exports.
AI Pet Video Generator
AI Pet Video Generator
Create viral, shareable pet videos from photos using AI-driven templates and instant HD exports for social platforms.
kinovi - Seedance 2.0 - Real Man AI Video
kinovi - Seedance 2.0 - Real Man AI Video
Free AI video generator with realistic human output, no watermark, and full commercial use rights.
Image 2 AI
Image 2 AI
OpenAI-powered image generation and editing tool for photorealistic visuals, accurate text rendering, and UI mockups.
Ampere.SH
Ampere.SH
Free managed OpenClaw hosting. Deploy AI agents in 60 seconds with $500 Claude credits.
Paper Banana
Paper Banana
AI-powered tool to convert academic text into publication-ready methodological diagrams and precise statistical plots instantly.
HookTide
HookTide
AI-powered LinkedIn growth platform that learns your voice to create content, engage, and analyze performance.
AI Video API: Seedance 2.0 Here
AI Video API: Seedance 2.0 Here
Unified AI video API offering top-generation models through one key at lower cost.
Gptimg2 AI
Gptimg2 AI
All-in-one AI studio for creating images and videos from text, images, or references.
wan 2.7-image
wan 2.7-image
A controllable AI image generator for precise faces, palettes, text, and visual continuity.
GenPPT.AI
GenPPT.AI
AI-driven PPT maker that creates, beautifies, and exports professional PowerPoint presentations with speaker notes and charts in minutes.
Hitem3D
Hitem3D
Hitem3D converts a single image into high-resolution, production-ready 3D models using AI.
Gobii
Gobii
Gobii lets teams create 24/7 autonomous digital workers to automate web research and routine tasks.
Create WhatsApp Link
Create WhatsApp Link
Free WhatsApp link and QR generator with analytics, branded links, routing, and multi-agent chat features.
Image to Video AI without Login
Image to Video AI without Login
Free Image to Video AI tool that instantly transforms photos into smooth, high-quality animated videos without watermarks.
Video Sora 2
Video Sora 2
Sora 2 AI turns text or images into short, physics-accurate social and eCommerce videos in minutes.
Palix AI
Palix AI
All-in-one AI platform for creators to generate images, videos, and music with unified credits.
Seedance 20 Video
Seedance 20 Video
Seedance 2 is a multimodal AI video generator delivering consistent characters, multi-shot storytelling, and native audio at 2K.
AI FIRST
AI FIRST
Conversational AI assistant automating research, browser tasks, web scraping, and file management through natural language.
Manga Translator AI
Manga Translator AI
AI Manga Translator instantly translates manga images into multiple languages online.
WhatsApp Warmup Tool
WhatsApp Warmup Tool
AI-powered WhatsApp warmup tool automates bulk messaging while preventing account bans.
ainanobanana2
ainanobanana2
Nano Banana 2 generates pro-quality 4K images in 4–6 seconds with precise text rendering and subject consistency.
Veemo - AI Video Generator
Veemo - AI Video Generator
Veemo AI is an all-in-one platform that quickly generates high-quality videos and images from text or images.
Remy - Newsletter Summarizer
Remy - Newsletter Summarizer
Remy automates newsletter management by summarizing emails into digestible insights.
TextToHuman
TextToHuman
Free AI humanizer that instantly rewrites AI text into natural, human-like writing. No signup required.
GLM Image
GLM Image
GLM Image combines hybrid AR and diffusion models to generate high-fidelity AI images with exceptional text rendering.

Nation-State Hackers Exploit Google Gemini AI for Cyberattacks

APT groups from China, North Korea, and Iran use Google Gemini for reconnaissance, malware coding, and phishing campaigns, Google GTIG reveals.