15 Sources
[1]
Attackers prompted Gemini over 100,000 times while trying to clone it, Google says
On Thursday, Google announced that "commercially motivated" actors have attempted to clone knowledge from its Gemini AI chatbot by simply prompting it. One adversarial session reportedly prompted the model more than 100,000 times across various non-English languages, collecting responses ostensibly
[2]
Hackers Are Trying to Copy Gemini via Thousands of AI Prompts, Google Reports
A new report from Google warns the industry of attempts to clone AI models. In a new Threat Tracker report published Thursday, Google said hackers are engaging in "distillation attacks," including one case in which they used more than 100,000 AI prompts to steal the company's technology for its
[3]
Google reports that state hackers from China, Russia and Iran are using Gemini in 'all stages' of attacks -- phishing lures, coding and vulnerability testing get AI underpinnings from hostile actors
Google's Gemini AI models have become a core component of state-sponsored hackers' attack vectors. Although AI use has been growing in white and black hat hacking in recent years, Google now says it's used in all parts of the attack process, from target acquisition to coding, social engineering
[4]
Google: China's APT31 used Gemini to plan US cyberattacks
A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot, Gemini, to auto-analyze vulnerabilities and plan cyberattacks against US organizations, the company says. While there's no indication that any of these attacks were
[5]
Google says hackers are abusing Gemini AI for all attacks stages
State-backed hackers are using Google's Gemini AI model to support all stages of an attack, from reconnaissance to post-compromise actions. Bad actors from China (APT31, Temp.HEX), Iran (APT42), North Korea (UNC2970), and Russia used Gemini for target profiling and open-source intelligence,
[6]
State-sponsored hackers love Gemini, Google says
Google restricts access for identified bad actors, but the report highlights AI's dual-use nature and emerging cybersecurity challenges. "AI" systems aren't just great for raising the price of your electronics, giving you wrong search results, and filling up your social media feed with slop. It's
[7]
AI malware, Gemini lures and more: Google reveals how hackers are actually using AI
State-sponsored groups are creating highly convincing phishing kits and social engineering campaigns If you've used any modern AI tools, you'll know they can be a great help in reducing the tedium of mundane and burdensome tasks. Well, it turns out threat actors feel the same way, as the latest
[8]
Hackers are using Gemini to target you, Google says
Google links Gemini use to recon, phishing, coding, and post-breach activity. Google says hackers are abusing Gemini to speed up cyberattacks, and it isn't limited to cheesy phishing spam. In a new Google Threat Intelligence Group report, it says state-backed groups have used Gemini across
[9]
State-Sponsored Hackers Using Popular AI Tools Including Gemini, Google Warns - Decrypt
Hackers are taking an interest in agentic AI to put AI fully in control of attacks. Google's Threat Intelligence Group (GTIG) is sounding the alarm once again on the risks of AI, publishing its latest report on how artificial intelligence is being used by dangerous state-sponsored hackers. This
[10]
Our new report details the latest ways threat actors are misusing AI.
Over the last few months, Google Threat Intelligence Group (GTIG) has observed threat actors using AI to gather information, create super-realistic phishing scams and develop malware. While we haven't observed direct attacks on frontier models or generative AI products from advanced persistent
[11]
Google has published a list of ways AI is currently being used by threat actors to more efficiently hack you
Some of it is reportedly from 'government-backed' entities, too. As AI continues to grow and make its way into everyday life, the alleged productivity gains do appear to be showing in some places. It just so happens that hacker groups are one of those places, and Google's Threat Intelligence has
[12]
Google says attackers used 100,000+ prompts to try to clone AI chatbot Gemini
Google says its flagship artificial intelligence chatbot, Gemini, has been inundated by "commercially motivated" actors who are trying to clone it by repeatedly prompting it, sometimes with thousands of different queries -- including one campaign that prompted Gemini more than 100,000 times. In a
[13]
Google warns attackers are wiring AI directly into live cyberattacks - SiliconANGLE
Google warns attackers are wiring AI directly into live cyberattacks A new report out today from the Google Threat Intelligence Group is warning that threat actors are moving beyond casual experimentation with artificial intelligence and are now beginning to integrate AI directly into operational
[14]
Hackers Are Hammering Google's Gemini With Prompts to Steal the LLM -- Every AI Company Should Be Worried
Google called the attacks "model extraction," a process Medium defines as when "an attacker distills the knowledge from your expensive model into a new, cheaper one they control." It's becoming an increasing threat to major AI companies that spend billions of dollars on training its models, but
[15]
Google Warns Against Thieves Using APIs to Clone AI Models | PYMNTS.com
In these attacks, threat actors use their legitimate access to a large language model (LLM) to extract information that can be used to train a new LLM, according to the post. By doing so, the attackers can develop their AI models at greater speed and lower cost. There are legitimate uses for
Share
Copy Link
Google's Threat Intelligence Group reveals that state-backed hackers from China, Russia, Iran, and North Korea are systematically exploiting Gemini AI for cyberattacks. One adversarial campaign bombarded the model with over 100,000 prompts attempting to clone its capabilities. The attacks span reconnaissance, phishing, malware development, and vulnerability testing, marking a shift in how AI tools enable offensive cyber operations at scale.
Google has disclosed that state-sponsored hackers from China, Russia, Iran, and North Korea are exploiting its Gemini AI model throughout every phase of cyberattacks, according to a new report from the Google Threat Intelligence Group published Thursday
1
. The revelation marks a significant escalation in how adversaries leverage AI tools for offensive operations, with threat actors using Gemini for reconnaissance, phishing lures creation, command and control development, vulnerability analysis, and data exfiltration3
. "The adversaries' adoption of this capability is so significant - it's the next shoe to drop," said John Hultquist, chief analyst for the Google Threat Intelligence Group4
.
Source: Tom's Hardware
Chinese government-backed hacking group APT31, also known as Violet Typhoon, employed a highly structured approach by prompting Gemini with an expert cybersecurity persona to automate vulnerability analysis and generate targeted testing plans against specific US-based targets
4
. In one documented case, APT31 used Hexstrike, an open-source red-teaming tool built on the Model Context Protocol, directing the model to analyze Remote Code Execution (RCE), WAF bypass techniques, and SQL injection test results3
. This integration with Gemini "automated intelligence gathering to identify technological vulnerabilities and organizational defense weaknesses," according to Google's report4
. While there's no indication these attacks succeeded, the activity "explicitly blurs the line between a routine security assessment query and a targeted malicious reconnaissance operation." Hultquist emphasized the concern: "The ability to operate across the intrusion and automating the development of vulnerability exploitation allows adversaries to move faster than defenders and hit a lot of targets"4
.
Source: SiliconANGLE
Beyond direct operational use, Google identified large-scale model extraction attempts targeting Gemini AI through what the industry calls distillation attacks
1
. One commercially motivated adversarial session prompted the model more than 100,000 times across various non-English languages, collecting responses to train a cheaper copycat model1
. Google considers this intellectual property theft, though the position carries some irony given that its LLM was built from materials scraped from the Internet without permission1
. The technique involves feeding an existing AI model thousands of carefully chosen prompts, collecting responses, and using those input-output pairs to train a smaller model that mimics the parent's behavior. "Model extraction and subsequent knowledge distillation enable an attacker to accelerate AI model development quickly and at a significantly lower cost," Google researchers noted5
. The attacks came from around the world, though Google declined to name suspects1
.
Source: BleepingComputer
Related Stories
Iranian threat actor APT42 leveraged Gemini for social engineering campaigns, using it to search for official emails of specific targets and conduct research into business partners of potential victims
3
. They fed Gemini biographical information to generate personas that might have credible reasons to engage with targets3
. North Korea primarily used Gemini as part of phishing attacks, profiling high-value targets within security and defense companies and attempting to find vulnerable individuals within their networks3
. Threat actors from China, Iran, Russia, and Saudi Arabia also used Gemini to produce political satire and propaganda, generating articles, memes, and images designed to influence Western audiences3
. While Google confirmed it hadn't seen these assets deployed into the wild, the company took the threat seriously enough to disable accounts associated with these activities3
.The report highlights a growing appetite among hackers for bespoke AI hacking tools and stolen API keys to access commercial models
3
. Google cited an underground toolkit called "Xanthorox," advertised as custom AI for cyber offensive campaigns capable of generating malicious malware code and constructing custom phishing campaigns. However, under the hood, Xanthorox is simply an API that leverages existing general AI models like Gemini3
. Because using these tools requires making numerous API calls, organizations with large allocations of API tokens have become prime targets for account hijacking, creating a black market for API keys and placing greater emphasis on securing employee access to AI tools3
. Hultquist warned that organizations must adapt: "We are going to have to leverage the advantages of AI, and increasingly remove humans from the loop, so that we can respond at machine speed"4
. Google has since disabled accounts and infrastructure tied to documented abuse and implemented targeted defenses in Gemini's classifiers to make future exploitation harder5
.Summarized by
Navi
[4]
[5]
31 Jan 2025•Technology

11 May 2026•Technology

05 Nov 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology