By using this site, you agree to our Privacy Policy and Terms of Use.
Accept
VellaTimesVellaTimesVellaTimes
  • News
    NewsShow More
    A modern server room with glowing blue data streams and a computer terminal displaying artificial intelligence and file system architecture.
    AWS Upgrades Storage for the AI Era With Amazon S3 Files
    April 11, 2026
    A glowing holographic brain surrounded by digital medical data in a high-tech laboratory setting.
    New Alzheimer’s Treatments Require a Multi-Target Approach
    April 11, 2026
    Small Canadian and German national flags sitting on a modern corporate boardroom table next to a glowing artificial intelligence hologram.
    Cohere and Aleph Alpha in Advanced AI Merger Talks
    April 11, 2026
    A glowing silicon microchip resting on a server rack inside a modern, high-tech data center with dramatic blue lighting.
    Google and Intel Deepen AI CPU Partnership to Advance Cloud Infrastructure
    April 11, 2026
    Two wild chimpanzees with tense, alert expressions facing each other across a fallen log in a dense African rainforest, symbolizing the division and rivalry within the Ngogo community.
    Uganda Chimpanzee Civil War: Deadly Split in the Ngogo Community
    April 11, 2026
  • Technology
    TechnologyShow More
    A modern server room with glowing blue data streams and a computer terminal displaying artificial intelligence and file system architecture.
    AWS Upgrades Storage for the AI Era With Amazon S3 Files
    April 11, 2026
    A glowing silicon microchip resting on a server rack inside a modern, high-tech data center with dramatic blue lighting.
    Google and Intel Deepen AI CPU Partnership to Advance Cloud Infrastructure
    April 11, 2026
    A glowing silicon wafer held by a robotic arm in a modern semiconductor manufacturing facility, representing advanced AI chip production.
    TSMC Reports 35% Q1 Revenue Jump Driven by Resilient AI Chip Demand
    April 11, 2026
    A glowing digital padlock and web browser window secured above a computer microchip, representing Google Chrome's hardware-bound cookie protection.
    Google Chrome Launches Device Bound Session Credentials to Stop Cookie Theft
    April 10, 2026
    A close-up view of a high-tech processor chip inside a brightly lit, modern data center server rack.
    Intel and Google Expand AI Infrastructure Partnership
    April 10, 2026
  • AI
    AIShow More
    Small Canadian and German national flags sitting on a modern corporate boardroom table next to a glowing artificial intelligence hologram.
    Cohere and Aleph Alpha in Advanced AI Merger Talks
    April 11, 2026
    A glowing holographic horse made of digital data streams galloping in a modern server room, representing Alibaba's HappyHorse AI video model.
    Alibaba AI Video Model Happy Horse Tops Global Rankings
    April 11, 2026
    A glowing digital padlock shattering into data fragments in a dimly lit corporate server room with flashing red warning lights.
    Mercor Data Breach: $10 Billion AI Startup Faces Lawsuits and Customer Exodus
    April 10, 2026
    A modern financial trading floor with glowing digital screens displaying downward stock market trends and a subtle artificial intelligence neural network graphic in the background.
    2026 Global Market Trends: AI Fears and Profit Shifts
    April 10, 2026
    A futuristic computer screen displaying glowing code in a modern, brightly lit server room, representing the newly launched ChatGPT Pro plan for Codex users.
    ChatGPT Pro Plan: $100 OpenAI Tier Launched for Codex
    April 10, 2026
  • Science
    ScienceShow More
    A glowing holographic brain surrounded by digital medical data in a high-tech laboratory setting.
    New Alzheimer’s Treatments Require a Multi-Target Approach
    April 11, 2026
    Two wild chimpanzees with tense, alert expressions facing each other across a fallen log in a dense African rainforest, symbolizing the division and rivalry within the Ngogo community.
    Uganda Chimpanzee Civil War: Deadly Split in the Ngogo Community
    April 11, 2026
    A split-screen visual contrasting a vibrant, healthy rainforest ecosystem with a wooden legal gavel, representing the intersection of nature and environmental law.
    Global Environmental Conservation Faces New Climate Challenges and Legal Shifts
    April 10, 2026
    A glowing DNA double helix with one highlighted genetic letter in a modern laboratory setting.
    Single DNA Letter Change Triggers Complete Sex Reversal in Mice
    April 10, 2026
    The Orion spacecraft capsule splashing down in the Pacific Ocean under three large orange and white parachutes during the Artemis II mission return.
    Artemis II Return to Earth: Crew Prepares for Historic Pacific Splashdown
    April 10, 2026
  • World
    WorldShow More
    Allu Arjun Commitment to Ethical Brand Partnerships
    Exploring Allu Arjun’s Commitment to Ethical Brand Partnerships
    December 18, 2023
    Orry aka Orhan Awatramani
    Orhan Awatramani ‘Orry’ Biography, Lifestyle and Rise to Fame
    December 8, 2023
    Alia Bhatt Latest Deepake Video Victim
    Alia Bhatt becomes latest victim of Deepfake Videos, Obscene Video goes Viral
    November 28, 2023
    Napoleon Movie Review
    Napoleon Movie Review: A Historical Epic by Ridley Scott Reviewed
    November 25, 2023
  • Bookmarks
Search
Category
  • News
  • Technology
  • AI
  • Science
  • World
Company
  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy
Resources
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
Reading: Google Reports Hackers Are Now “Wiring” Gemini AI Directly Into Live Cyberattacks
Share
Notification Show More
Font ResizerAa
VellaTimesVellaTimes
Font ResizerAa
  • News
  • Technology
  • AI
  • Science
  • World
Search
  • Explore
    • News
    • Technology
    • AI
    • Science
    • World
  • Useful Links
    • About Us
    • Contact Us
    • Fact Checking Policy
    • Terms & Conditions
    • Privacy Policy
    • Copyright Policy
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
© 2022 VellaTimes • All Rights Reserved.
News

Google Reports Hackers Are Now “Wiring” Gemini AI Directly Into Live Cyberattacks

Sameer Katoch
Last updated: 16/02/2026
Sameer Katoch
Share
6 Min Read
A computer monitor in a security operations center displaying malicious code making a direct API call to an AI model, with analysts working in the background.

State-backed hacking groups and cybercriminals have moved beyond simple experimentation with artificial intelligence and are now integrating it into every stage of their attack chains, according to a new report released Thursday, February 12, 2026, by the Google Threat Intelligence Group (GTIG).

The report reveals that adversaries from China, Iran, North Korea, and Russia are actively using Google’s Gemini AI models to accelerate operations, ranging from initial reconnaissance and phishing to malware development and technical troubleshooting. While AI has not yet fully replaced human operators, Google warns that attackers are now “wiring” AI directly into their malicious tools to automate complex tasks and evade detection.

State-Sponsored Groups Leading the Charge

Google’s researchers identified specific government-backed groups that are leveraging generative AI to boost their productivity and effectiveness.

  • North Korea (UNC2970): This group is using Gemini to synthesize open-source intelligence (OSINT) on targets in the defense and cybersecurity sectors. They profile high-value individuals by mapping technical job roles and salary information to create highly convincing phishing personas, often masquerading as corporate recruiters.
  • Iran (APT42): Known for aggressive social engineering, this group uses Gemini to conduct “rapport-building phishing.” They generate detailed biographies and personas to establish trust with victims before delivering malicious payloads. They also use the tool to translate content and debug their own malicious code.
  • China (APT31 & UNC795): These groups have been observed using “expert cybersecurity personas” to prompt Gemini for vulnerability analysis. In one case, APT31 directed the model to analyze specific vulnerabilities—such as SQL injection and Remote Code Execution (RCE)—against U.S.-based targets. UNC795 utilized the AI for troubleshooting code and researching technical capabilities for intrusions.
  • Russia: The report notes that Russian actors, along with those from other nations, are using AI to generate political satire and propaganda, though these efforts have not yet produced “breakthrough” capabilities in information operations.

New Malware “Calls” AI for Code

One of the most significant findings in the report is the emergence of malware that makes direct API calls to AI models during an attack.

Google identified a malware family dubbed HONESTCUE, a downloader and launcher that sends a hard-coded prompt to the Gemini API. The AI responds by generating C# source code, which the malware then compiles and executes directly in the computer’s memory. This “fileless” approach helps the attackers avoid leaving artifacts on the victim’s hard drive, making traditional detection more difficult.

Another threat, COINBAIT, is a sophisticated phishing kit masquerading as a cryptocurrency exchange. Evidence suggests this kit was built using AI code generation tools like “Lovable AI.” The malware includes verbose logging messages that appear to be generated by Large Language Models (LLMs), allowing attackers to track their data theft in real time.

“ClickFix” and Model Theft

Cybercriminals are also abusing the public sharing features of AI platforms. In a tactic known as ClickFix, attackers generate realistic-looking instructions for fixing common computer issues—such as clearing disk space—and host them on trusted AI platforms using shareable links. When victims follow the instructions, they unknowingly copy and paste malicious commands into their system terminals, installing information-stealing malware like AMOS (ATOMIC) on macOS and Windows devices.

Beyond operational attacks, Google observed a rise in “distillation attacks” or model extraction. This involves adversaries sending massive volumes of queries—in one case, over 100,000 prompts—to a proprietary model like Gemini. By analyzing the model’s responses, attackers aim to “clone” its reasoning capabilities and logic to train their own systems without incurring the high costs of development.

Industry Reaction and Defense

Steve Miller, AI threat lead at GTIG, stated that while attackers are experimenting with new ways to bypass safeguards, Google is continuously updating its defenses. The company has disrupted campaigns by disabling accounts and assets associated with these actors.

However, not all experts are convinced of the severity. Dr. Ilia Kolochenko, CEO of ImmuniWeb, criticized the report as “poorly orchestrated PR,” arguing that while AI can automate simple processes, it has not yet become capable of executing a full “cyber kill chain” on its own. He also warned that Google’s awareness of this abuse could potentially expose the company to liability for damages caused by these AI-enabled attacks.

TAGGED: AI security, cyberattacks, cybersecurity news, Gemini AI, HONESTCUE, malware
Share This Article
Facebook Twitter Whatsapp Whatsapp Telegram Copy Link
By Sameer Katoch
As the Founder of VellaTimes and an avid traveler, I'm passionate about the daily news events happening globally. With over five years of experience in the writing field, I am committed to delivering top-notch news that satisfies your daily news intake.
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Most Read

YouTubers Sue Snap Over AI Training Copyright Claims

January 27, 2026

RAM shortage drives memory prices higher into 2028

January 19, 2026

GPT-5.3 Codex launches as faster agentic coding model

February 14, 2026

CAG-170 gut bacteria linked to good health in study

February 15, 2026

Global Water Crisis: Drought Impacts and Recovery Efforts

March 9, 2026

Ofcom WhatsApp probe examines Meta data responses in UK

January 24, 2026

Related News

A modern server room with glowing blue data streams and a computer terminal displaying artificial intelligence and file system architecture.
News

AWS Upgrades Storage for the AI Era With Amazon S3 Files

Rakesh Paul Rakesh Paul April 11, 2026
A glowing holographic brain surrounded by digital medical data in a high-tech laboratory setting.
News

New Alzheimer’s Treatments Require a Multi-Target Approach

Nisha Pradhan Nisha Pradhan April 11, 2026
Small Canadian and German national flags sitting on a modern corporate boardroom table next to a glowing artificial intelligence hologram.
News

Cohere and Aleph Alpha in Advanced AI Merger Talks

Sameer Katoch Sameer Katoch April 11, 2026

About Us

VellaTimesVellaTimesVellaTimes

VellaTimes is a leading news portal that covers the latest trending news in technology, lifestyle, entertainment, automobiles, travel, and sports.

Explore

  • News
  • Technology
  • AI
  • Science
  • World

Useful Links

  • About Us
  • Contact Us
  • Fact Checking Policy
  • Terms & Conditions
  • Privacy Policy
  • Copyright Policy

Subscribe Us

Subscribe to our newsletter for the Latest News and Top Stories!

© 2022 VellaTimes • All Rights Reserved.
  • Home
  • Web Stories
  • Bookmarks
  • Interests
  • Disclaimer
  • Sitemap
adbanner
AdBlocker Detected
Our site is an advertising supported site. Please whitelist us to support our work.
Okay, I'll Whitelist