• News/
  • https://www.bleepingcomputer.com/news/security/google-says-hackers-abuse-gemini-ai-to-empower-their-attacks/

Google says hackers abuse Gemini AI to empower their attacks

BleepingComputer
·
Bill Toulas
·
Published Feb 1, 2025
·
Updated

Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity and to conduct research on potential infrastructure for attacks or for reconnaissance on targets. Google's Threat Intelligence Group (GTIG) detected government-linked advanced persistent threat (APT) groups using Gemini primarily for productivity gains rather than to develop or conduct novel AI-enabled cyberattacks that can bypass traditional defenses. Threat actors have been trying to leverage AI tools for their attack purposes to various degrees of success as these utilities can at least shorten the preparation period. Google has identified Gemini activity associated with APT groups from more than 20 countries but the most prominent ones were from Iran and China. Among the most common cases were assistance with coding tasks for developing tools and scripts, research on publicly disclosed vulnerabilities, checking on technologies (explanations, translation), finding details on target organizations, and searching for methods to evade detection, escalate privileges, or run internal reconnaissance in a compromised network. Google says APTs from Iran, China, North Korea, and Russia, have all experimented with Gemini, exploring the tool's potential in helping them discover security gaps, evade detection, and plan their post-compromise activities. These are summarized as follows: Google also mentions having observed cases where the threat actors attempted to...

Read full article

Affected Software

3 affected components
DeepSeek R1
DeepSeek V3
Alibaba Qwen=2.5
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how hackers are leveraging Google's Gemini AI to enhance their cyber attacks.

2

What security implications are discussed?

The article highlights the potential for state-sponsored groups to use AI for infrastructure reconnaissance and to increase the efficiency of their attacks.

3

What products or software are affected?

The affected products include Google's Gemini AI and various AI tools from DeepSeek and Alibaba, specifically DeepSeek R1, DeepSeek V3, and Alibaba Qwen 2.5.

4

Who is behind the abusive use of Gemini AI?

The article mentions multiple state-sponsored groups as the primary actors abusing Gemini AI for malicious purposes.

5

How does AI contribute to the hackers' capabilities?

AI tools like Gemini are used by hackers to improve their research, target reconnaissance, and overall attack productivity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203