Home Cyber Security

Google Warns AI Is Becoming an Active Participant in Cyber Attacks

Google Threat Intelligence Group (GTIG) has warned that cybercriminals and state-backed hacking groups are rapidly evolving from simply experimenting with artificial intelligence to embedding it directly into offensive cyber operations.

In its latest AI Threat Tracker report, GTIG said threat actors linked to China, North Korea and Russia are now using AI for vulnerability discovery, malware development, reconnaissance and information operations at a scale and speed that would have been difficult to achieve manually.

One of the report’s most significant findings is GTIG’s identification of what it believes is the first observed zero-day exploit likely developed with the assistance of AI. According to the report, cybercriminals used AI-generated techniques to identify and weaponise a two-factor authentication bypass vulnerability in a popular open-source administration platform.

GTIG noted that while traditional security tools remain effective at detecting low-level coding errors and implementation flaws, frontier large language models are increasingly capable of identifying higher-level semantic logic flaws that are strategically dangerous but difficult for conventional scanners to detect.

The report also highlights how threat actors are now using AI to improve malware evasion and operational resilience. Researchers observed PRC-linked group APT27 leveraging Gemini to accelerate development of infrastructure management tools designed to support operational relay box (ORB) networks using residential IP infrastructure to disguise attack origins.

Meanwhile, Russia-linked actors targeting Ukrainian organisations were found deploying malware families containing large volumes of AI-generated decoy code designed to frustrate analysis and bypass detection systems. GTIG said malware families such as CANFAIL and LONGSTREAM contained coherent but inactive administrative code inserted purely to camouflage malicious functionality.

The report also points to the emergence of AI-enabled autonomous malware operations. GTIG detailed analysis of PROMPTSPY, an Android backdoor capable of using Gemini to autonomously interpret user interface states, calculate on-screen coordinates and execute gestures such as clicks and swipes without direct human guidance.

Researchers said PROMPTSPY could also capture biometric authentication gestures and dynamically update infrastructure such as Gemini API keys and command-and-control servers to maintain persistence.

Beyond malware, GTIG warned that AI is increasingly being integrated into reconnaissance and phishing workflows. Threat actors were observed using large language models to map organisational hierarchies, identify third-party relationships and research high-value targets in order to craft more convincing phishing campaigns.

The report also describes a shift toward “agentic workflows”, where AI systems move beyond acting as research assistants and begin autonomously orchestrating offensive operations. GTIG identified suspected PRC-linked actors using agentic frameworks such as Hexstrike and Strix to automate reconnaissance and vulnerability validation against targets in Asia.

In parallel, Google warned that threat actors are increasingly attempting to industrialise access to frontier AI models. The report outlines how attackers are using automated account registration pipelines, proxy relays and API aggregation services to bypass safety controls, billing restrictions and account bans across commercial LLM platforms.

The findings also highlight growing risks across AI supply chains. GTIG documented malicious OpenClaw skills capable of executing unauthorised commands and stealing sensitive data, as well as broader compromises affecting GitHub repositories and AI-related packages including LiteLLM and BerriAI.

Despite the escalating sophistication of these attacks, Google said AI is also becoming an important defensive capability. The company highlighted projects such as Big Sleep, an AI agent designed to proactively identify vulnerabilities, and CodeMender, an experimental AI system capable of automatically patching critical flaws.