Google Threat Intelligence Group Reports Surge in AI Misuse for Cyber Operations
The Google Threat Intelligence Group has published new findings showing a global rise in the misuse of artificial intelligence by both state-sponsored and private-sector threat actors. The report identifies widespread use of AI tools to enhance phishing, reconnaissance, and malware creation activities across multiple regions.
According to the report, government-backed actors from North Korea, Iran, China, and Russia are using large language models to generate realistic phishing content, conduct target research, and support coding tasks. These actors leveraged AI systems, including Gemini, to automate reconnaissance and improve the credibility of their social engineering campaigns. Google has taken actions to disable accounts and assets linked to these malicious operations.
The report also highlights a growing number of model extraction or “distillation” attacks, in which adversaries attempt to replicate the capabilities of proprietary AI models through repeated API queries. These activities were primarily attributed to private-sector entities and researchers seeking to clone model logic. Google stated that it has detected and mitigated these attacks to protect its AI systems.
In addition, the report outlines experimental uses of AI in malware development. Examples include the HONESTCUE malware family, which used Gemini’s API to generate code for secondary payloads, and the COINBAIT phishing kit, likely built using AI code generation tools. These cases illustrate how attackers are integrating AI into traditional cyber operations to increase speed and efficiency.
Google noted that while no direct attacks on frontier AI models have been observed from advanced persistent threat groups, the company continues to strengthen its security measures to prevent misuse. GTIG emphasized that organizations operating AI services should monitor for extraction patterns and apply safeguards to protect proprietary systems.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly, AI Policy Brief or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Oct 2 Suspected Chinese spies impersonate AI policy figures in phishing campaign Oct 2 AI Agents Tried to Access Canadian Government Archive Site Oct 2 Nuix Showcases Neo Financial Crime Tools at Sibos 2026 Oct 1 OpenAI Links Model Reasoning Extraction Campaign to Moonshot AI Oct 1 Ocrolus Adds Resistant AI Document Fraud Detection to DetectMore from AI Safety
Oct 2 OpenAI Parts Ways With Three Safety Researchers Oct 1 OpenAI Links Model Reasoning Extraction Campaign to Moonshot AI Sep 30 Chinese AI Agents Deceived Evaluators in Controlled Tests Sep 29 Florida Attorney General Seeks to Block New OpenAI Model Development Sep 29 UK Safety Test Finds GPT-6 Astra Conducted Simulated Supply Chain AttacksCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Market report
2025 Generative AI in Professional Services Report
Thomson Reuters
This report by Thomson Reuters explores the integration and impact of generative AI technologies, such as ChatGPT and Microsoft Copilot, within the professional services sector. It highlights the growing adoption of GenAI tools across industries like legal, tax, accounting, and government, and discusses the challenges and opportunities these technologies present. The report also examines professionals' perceptions of GenAI and the need for strategic integration to maximize its value.
Read moreYou may also like
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
Chinese AI Agents Deceived Evaluators in Controlled Tests
Suspected Chinese spies impersonate AI policy figures in phishing campaign
UK Safety Test Finds GPT-6 Astra Conducted Simulated Supply Chain Attacks
Researchers Link OpenAI Agents to May RubyGems Attack
Daily AI Brief: the AI news that matters, in your inbox.