Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitystate-sponsored-espionageinitial-access-methodgovernment-diplomatic-threat

Google Reports Nation-State Hackers Using Gemini AI to Accelerate Reconnaissance and Attack Support

Updated 3mo agoFirst seen Feb 12, 20266 sources

Google’s Threat Intelligence Group (GTIG) reported that multiple state-backed threat actors are abusing Google’s Gemini generative AI to speed up key phases of the attack lifecycle, particularly target reconnaissance and profiling. GTIG said it observed North Korea-linked UNC2970 using Gemini to synthesize OSINT and build detailed profiles of high-value targets—researching major cybersecurity and defense companies, mapping technical job roles, and even gathering salary information—to support campaign planning and enable more tailored social engineering.

GTIG also assessed that other government-aligned groups in China, North Korea, and Iran are using Gemini for tasks including coding/scripting, researching publicly known vulnerabilities, and supporting post-compromise activity. One example cited involved a Chinese actor using Gemini to compile information on specific individuals in Pakistan and to collect structural data on separatist organizations; Google said it disabled the assets used in that activity, while noting similar Pakistan-focused targeting persisted. GTIG characterized this AI-enabled workflow as blurring the line between routine research and malicious reconnaissance, allowing actors to move from initial research to active targeting faster and at broader scale.

Share:
Google Reports Nation-State Hackers Using Gemini AI to Accelerate Reconnaissance and Attack Support
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 12, 20264mo ago

Google reports state-backed hackers using Gemini across attack lifecycle

On February 12, 2026, Google Threat Intelligence Group publicly reported that threat actors linked to China, North Korea, Iran, and other countries were using Gemini to accelerate reconnaissance, target profiling, social engineering, vulnerability analysis, and malware development. Google said the activity mostly improved attacker productivity rather than enabling fully autonomous or novel AI-driven intrusions.

Google disables accounts tied to Gemini abuse by threat actors

Google said it disabled assets and accounts associated with malicious use of Gemini by state-backed and criminal actors and added defenses to harden the service against abuse. The action accompanied findings that attackers were using Gemini for reconnaissance, phishing support, vulnerability research, and malware-related tasks.

Google detects and disrupts large-scale Gemini model extraction attempts

Before publishing its February 2026 report, Google DeepMind and GTIG detected and blocked model extraction or distillation attacks against Gemini, including one campaign involving more than 100,000 prompts. Google said it disrupted the activity as part of broader defenses against theft of proprietary model capabilities.

Nov 1, 20258mo ago

Google identifies COINBAIT AI-assisted phishing kit

In November 2025, Google identified COINBAIT, an AI-assisted phishing kit impersonating a cryptocurrency exchange. Reporting linked the kit at least in part to UNC5356.

Sep 1, 202510mo ago

Google tracks HONESTCUE malware using Gemini API for second-stage code

In September 2025, Google observed a malware family it named HONESTCUE that used the Gemini API to generate malicious C# second-stage functionality and execute it in a fileless manner. Google said the malware was not yet tied to a known threat cluster.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

32 LINKEDOpen in app
Affected products
5 linked
VirustotalCloudflareNetNetWinrar
Organizations
13 linked
GoogleShutterstockDiscordXBOWCato NetworksCloudflareAnthropicRecorded FutureLovablePraetorianHuntressSecurity AffairsThrive Studios ID
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Reports Nation-State Hackers Using Gemini AI to Accelerate Reconnaissance and Attack Support | Mallory