Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity and to conduct research on potential infrastructure for attacks or for reconnaissance on targets. Google's Threat Intelligence Group (GTIG) detected government-linked advanced persistent threat (APT) groups using Gemini primarily for productivity gains rather than to develop or conduct novel AI-enabled cyberattacks that can bypass traditional defenses. Threat actors have been trying to leverage AI tools for their attack purposes to various degrees of success as these utilities can at least shorten the preparation period. Google has identified Gemini activity associated with APT groups from more than 20 countries but the most prominent ones were from Iran and China. Among the most common cases were assistance with coding tasks for developing tools and scripts, research on publicly disclosed vulnerabilities, checking on technologies (explanations, translation), finding details on target organizations, and searching for methods to evade detection, escalate privileges, or run internal reconnaissance in a compromised network. Google says APTs from Iran, China, North Korea, and Russia, have all experimented with Gemini, exploring the tool's potential in helping them discover security gaps, evade detection, and plan their post-compromise activities. These are summarized as follows: Google also mentions having observed cases where the threat actors attempted to...
Google says hackers abuse Gemini AI to empower their attacks
BleepingComputer
·Bill Toulas
·Published Feb 1, 2025
·Updated
Affected Software
3 affected components
DeepSeek R1
DeepSeek V3
Alibaba Qwen=2.5
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how hackers are leveraging Google's Gemini AI to enhance their cyber attacks.
2
What security implications are discussed?
The article highlights the potential for state-sponsored groups to use AI for infrastructure reconnaissance and to increase the efficiency of their attacks.
3
What products or software are affected?
The affected products include Google's Gemini AI and various AI tools from DeepSeek and Alibaba, specifically DeepSeek R1, DeepSeek V3, and Alibaba Qwen 2.5.
4
Who is behind the abusive use of Gemini AI?
The article mentions multiple state-sponsored groups as the primary actors abusing Gemini AI for malicious purposes.
5
How does AI contribute to the hackers' capabilities?
AI tools like Gemini are used by hackers to improve their research, target reconnaissance, and overall attack productivity.