BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Use Google’s Gemini AI for Cyber Recon

Threat actors misuse Gemini AI for reconnaissance, exploitation, and model theft.

  • Google’s threat intelligence team observed the North Korean hacking group UNC2970 using the generative AI model Gemini to profile high-value cybersecurity and defense targets.
  • Multiple state-backed threat actors, including clusters from China and Iran, are using AI to automate reconnaissance, code exploits, and craft social engineering campaigns.
  • Malicious tools like the HONESTCUE downloader weaponize Gemini’s API to generate and execute malicious C# code directly in memory, leaving minimal forensic traces.
  • Attackers are conducting large-scale model extraction attacks, using over 100,000 queries to replicate proprietary AI model behavior, a risk highlighted by security researchers.

Google’s Threat Intelligence Group reported on Thursday that the North Korean UNC2970 hacking group weaponized its Gemini AI for malicious cyber reconnaissance. This state-backed actor used the model to synthesize public intelligence on defense firms and map technical job roles for targeted phishing.

- Advertisement -

The activity, detailed in a report, blurs the line between professional research and malicious profiling. Consequently, it enables the group to identify soft targets and craft convincing personas for initial compromise.

Multiple other threat actors have integrated Gemini into their workflows, according to the findings. The Chinese-linked APT42 used it to develop a Python-based Google Maps scraper and research a WinRAR vulnerability.

APT41 and UNC795 also employed the AI to troubleshoot exploit code and develop web shells. The financially motivated UNC5356 cluster was linked to an AI-generated phishing kit called COINBAIT that mimics a cryptocurrency exchange.

Google also identified the HONESTCUE malware, which calls Gemini’s API to generate its secondary stage functionality. This fileless payload is compiled and executed directly in memory using the .NET CSharpCodeProvider framework.

- Advertisement -

Meanwhile, the company disrupted model extraction attacks involving over 100,000 prompts aimed at Gemini. A proof-of-concept extraction achieved 80.1% accuracy with just 1,000 queries, demonstrating the threat. Security researcher Farida Shafik noted, “Every query-response pair is a training example for a replica.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

RaveDAO Denies Manipulation as Exchanges Probe Token Plunge

RaveDAO has denied responsibility for its RAVE token's extreme price volatility following allegations of...

Robinhood Soars 31% on SEC Rule Change and Crypto Rally

Robinhood (HOOD) stock surged 31% this week, making it the top performer in the...

Bitcoin Eyes $82K by April’s End Amid Volatility

Analysts predict a final push for Bitcoin towards the $78,000-$80,000 zone before a potential...

Worldcoin Drops 13% Despite Zoom, Docusign ID Deals

Worldcoin (WLD) dropped 13.4% to roughly $0.28 on Friday, contrasting with a broader crypto...

Bitcoin Soars Past Key Resistance; Traders See 69% Chance of $84K

Bitcoin surged 2.7%, breaking a key descending resistance line that had suppressed its price...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading