Introduction
State-sponsored hackers are increasingly leveraging sophisticated artificial intelligence tools to escalate their cyberattack capabilities. According to a recent report by Google’s Threat Intelligence Group (GTIG), threat actors from nations including Iran, North Korea, China, and Russia are utilizing AI models such as Google’s Gemini to enhance phishing campaigns, perform detailed reconnaissance, and develop advanced malware.
AI Integration in Cyberattack Lifecycle
The quarterly AI Threat Tracker report highlights that government-backed hackers have integrated AI across all stages of their operations: from reconnaissance and social engineering to malware development. Insights gathered during the final quarter of 2025 reveal a growing reliance on large language models (LLMs) to accelerate and refine attack methodologies.
GTIG researchers noted, “For government-backed threat actors, large language models have become essential tools for technical research, targeting, and the rapid generation of nuanced phishing lures.” This marks a new era in cyber threats where AI plays a pivotal role in crafting highly convincing attack vectors.
State-Sponsored Reconnaissance Targeting the Defense Sector
The Iranian hacking group APT42 has reportedly exploited Gemini to bolster reconnaissance efforts and social engineering tactics. By generating official-looking email addresses and conducting in-depth research, APT42 creates credible pretexts to engage targets effectively. They develop personas and scenarios that use natural language translations to bypass traditional phishing detection mechanisms, such as grammar and syntax checks.
Similarly, the North Korean state-sponsored actor UNC2970 focuses on defense sector targets and impersonation of corporate recruiters. Utilizing Gemini, UNC2970 profiles high-value individuals by gathering detailed information on cybersecurity and defense firms, including specific job roles and salary data. GTIG emphasizes that such activities “blur the distinction between routine professional research and malicious reconnaissance,” enabling tailored and convincing phishing attempts.
Rise in Model Extraction Attacks
Beyond operational misuse, Google DeepMind and GTIG have observed a surge in model extraction or “distillation” attacks aimed at stealing AI intellectual property. One notable campaign targeted Gemini’s reasoning capabilities using over 100,000 prompts designed to replicate its logic across multiple languages.
While no direct attacks on leading-edge models from advanced persistent threat (APT) groups have been detected, numerous extraction attempts from private sector actors and researchers seeking to clone proprietary AI logic have been disrupted. Google has deployed real-time defenses to protect internal reasoning processes against these intellectual property theft attempts.
Emergence of AI-Integrated Malware
GTIG identified malware known as HONESTCUE that uses Gemini’s API to outsource functionality generation. This malware employs a multi-layered obfuscation strategy to evade traditional network detection and static analysis. Acting as a downloader and launcher, HONESTCUE sends prompts to Gemini’s API and receives C# source code responses, which are then compiled and executed directly in memory without leaving traces on disk.
Additionally, the COINBAIT phishing kit, likely accelerated by AI code generation tools, impersonates major cryptocurrency exchanges to harvest credentials. This kit was reportedly developed using the AI platform Lovable AI.
Abuse of AI Chat Platforms in Social Engineering
A novel campaign named ClickFix, first observed in December 2025, exploits public sharing features of generative AI platforms including Gemini, ChatGPT, Copilot, DeepSeek, and Grok. Attackers create realistic instructions for common computer tasks containing embedded malicious scripts. These AI chat transcripts are shared via trusted domains, enabling the distribution of ATOMIC malware targeting macOS systems.
Underground Market for Stolen AI Credentials
Investigations into underground forums in English and Russian reveal a persistent demand for AI-enabled hacking tools. State-sponsored actors and cybercriminals often rely on stolen API keys to access commercial AI products rather than developing proprietary models.
For example, the toolkit “Xanthorox” advertises itself as a custom AI for autonomous malware and phishing operations. However, GTIG found that it is powered by commercial AI models like Gemini, accessed through stolen credentials.
Google’s Defensive Measures and Commitment
In response, Google has actively disabled accounts linked to malicious activity and enhanced the robustness of their AI classifiers and models to resist exploitation. The company reaffirmed its commitment to responsible AI development by taking proactive steps to disrupt cybercriminal operations and improve defenses against misuse.
Despite these advancements in attack sophistication, GTIG states no breakthrough AI capabilities have fundamentally changed the cyber threat landscape as of now. The findings underscore the dynamic nature of AI in cybersecurity, with defenders and attackers continually adapting to new technological capabilities.
Implications for Enterprise Security
For enterprise security teams, particularly in regions like Asia-Pacific where Chinese and North Korean threat actors remain active, the report highlights the urgent need to strengthen safeguards against AI-augmented social engineering and reconnaissance attacks. The evolution of AI tools in cybercrime necessitates enhanced vigilance and updated defense strategies.
Fonte: ver artigo original

Microsoft Expands Cloud and AI Services to Boost Indonesia’s Long-Term AI Strategy
xAI Launches Grok 4.1 Fast API Amid Controversy Over AI’s Flattering Responses About Elon Musk
Gridcare Secures $13.3M to Uncover Hidden 100GW Data Center Capacity in Electrical Grid
Claude Code Creator Unveils Revolutionary AI-Powered Workflow Transforming Software Development