Threat actors are increasinly relying on large language models (LLMs) to plan and execute cyber-attacks, new search from Google Threat Intelligence Group (GTIG) has found.
The group’s most recent AI Threat Tracker found that state-backed cyber gangs are already emloying AI for cyber espionage and attacks, often turning to Google’s own Gemini models.
Threat groups typically use LLMs to research potentil targets, investigation vulnerabilities, and create and edit code and scripts.
Google’s researchers said that LLMs have “become essential tools” for government-backed threat actors, who use them for “technical reserch, targeting, and the rapid generation of nuanced phishing lures.”
The research found an array of breaches of Google Gemini’s terms of serive by advanced persistent threat (APT) groups using the AI model for cyber-attacks.
Researchers observed mode extraction attacks, which are also known as distillation attacks, on Google’s AI models, where threat actors aimed to gain insights into a model’s underlying reasoning and algorithmic processes.
These insights cn be used to accelerate AI model development, essentially relying on the theft of itnellectual property to create similar AI models that threat actors can manipulate for malicious purposes.
Further, while Google has seen threat actors use Gemini, and other AI models, to power their attacks, GTIG has improved its understanding of how this is done in direct and indirect links between activity in the real world and the misuse of Gemini for malicious purposes.
LLMs were used throughout the attack lifestyle; a China-based threat actor misued AI tools to generate detailed individuals on potnetial targets, while an Iranian-backed actor leveraged several AI tools to augment reconnaissance and social engineering tactics.
Another Chinese-based theat actor use Gemini to investigate vulnerabilities and generate automated testing plans to gather defensive weaknesses. A different threat actor group used Gemini throughout its entire lifecycle, troubleshooting their code, conducting reserch, and creating technical capabilities for their attack.
While threat actors continue to use AI to enhance their cyber-attacks, GTIG is still only seeing experiemntation when it comes to AI-generated malware.
“While we have not encountered experimental AI-enabled techniques resulting in revolutionary paradigm shifts in the threat landscape, these proof-of-concept malware families are early indicators of how threat actors can implement AI techniques as part of future operations,” the researchers said.
Recommended
- AI Is Driving Another Wave of Cyber-crime
- Fraud-as-a-Service Driving ‘Mega’ Cyber-attacks
- ICO: Data Protection Not An Excuse When Tackling Scams, Fraud
There have been advancements in this arena, however, with HONESTCUE malware being found to call on Gemini to generate code for its second stage of attack. While this has yet to be seen in the wild, GTIG believes that a threat actor group is continually testing these capabilities for future attacks.
However, researchers did identify COINBAIT, an AI-generated phishing kit, in November 2025, which GTIG researchers say has signs to being generated using Loveable AI, a vibe coding platform.
The AI Threat Report shows that threat actors continue to find novel ways of using AI to enhance their capabilities and attack efficicacy. While certain tactics, like AI-generated malware, are still in the testing phase, this could soon change as models are continually manipulated for malicious activities.





