Skip to main content
  1. Home
  2. Computing
  3. News

Hackers are using Gemini to target you, Google says

Google links Gemini use to recon, phishing, coding, and post-breach activity.

Add as a preferred source on Google
Close-up of hands on a laptop keyboard in a dark room.
Dmitry Tishchenko / 123RF

Google says hackers are abusing Gemini to speed up cyberattacks, and it isn’t limited to cheesy phishing spam. In a new Google Threat Intelligence Group report, it says state-backed groups have used Gemini across multiple phases of an operation, from early target research to post-compromise work.

The activity spans clusters linked to China, Iran, North Korea, and Russia. Google says the prompts and outputs it observed covered profiling, social engineering copy, translation, coding help, vulnerability testing, and debugging when tools break during an intrusion. Fast help on routine tasks can still change the outcome.

AI help, same old playbook

Google’s researchers frame the use of AI as acceleration, not magic. Attackers already run recon, draft lures, tweak malware, and chase down errors. Gemini can tighten that loop, especially when operators need quick rewrites, language support, or code fixes under pressure.

Recommended Videos

The report describes Chinese-linked activity where an operator adopted an expert cybersecurity persona and pushed Gemini to automate vulnerability analysis and produce targeted test plans in a made-up scenario. Google also says a China-based actor repeatedly used Gemini for debugging, research, and technical guidance tied to intrusions. It’s less about new tactics, more about fewer speed bumps.

The risk isn’t just phishing

The big shift is tempo. If groups can iterate faster on targeting and tooling, defenders get less time between early signals and real damage. That also means fewer obvious pauses where mistakes, delays, or repeated manual work might surface in logs.

Google also flags a different threat that doesn’t look like classic scams at all, model extraction and knowledge distillation. In that scenario, actors with authorized API access hammer the system with prompts to replicate how it performs and reasons, then use that knowledge to train another model. Google frames it as commercial and intellectual property harm, with potential downstream risk if it scales, including one example involving 100,000 prompts aimed at replicating behavior in non-English tasks.

What you should watch next

Google says it has disabled accounts and infrastructure tied to documented Gemini abuse, and it has added targeted defenses in Gemini’s classifiers. It also says it continues testing and relies on safety guardrails.

For security teams, the practical takeaway is to assume AI-assisted attacks will move quicker, not necessarily smarter. Track sudden improvements in lure quality, faster tooling iteration, and unusual API usage patterns, then tighten response runbooks so speed doesn’t become the attacker’s biggest advantage.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Layr is a new macOS clipboard manager that replaces hotkeys with trackpad gestures
This new Mac app opens clipboard history with a four-finger tap instead of a keyboard shortcut
Cursor open on Mac

macOS users already have several clipboard manager options, including Paste and Maccy. Most of them work well, but they are usually built around keyboard shortcuts. That is useful for keyboard-heavy users, but it can feel out of place for users who rely on the trackpad for most of their work.

Layr, a new clipboard manager from the developer behind Declutr, takes a different approach. Rather than assigning a keyboard shortcut to open the clipboard history, the app lets users bring up a clipboard overlay with a four-finger tap on the trackpad.

Read more
YouTube’s AI content labels are getting a much-needed makeover
No more hunting through descriptions. YouTube's AI labels are finally moving front and center.
YouTube ai declaration longform video

This year’s Google I/O marked the transition of Google from a search company to a fully AI-focused company. The company launched several AI tools, but the one that matters the most for YouTubers is Google Omni, built for video generation and editing. 

While tools like Omni lower the barrier for creators, which is a good thing, it also results in the platform being inundated with low-effort AI content. The company understands that this will annoy a large percentage of its users, so it has been asking creators to disclose AI-generated content since 2024. 

Read more
AI models have a religion favoritism problem, and new research exposes it
AI models are subtly steering users toward certain religions, and most people have no idea it's happening.
Artificial Intelligence

A new research consortium has found something worth paying attention to: when you ask AI about grief, love, loss, or moral decisions, it almost never brings religion into the conversation.

The Consortium for Evaluation of Faith and Ethics in AI (CEFE-AI), a collaboration among researchers at Brigham Young University, Baylor University, the University of Notre Dame, and Yeshiva University, published its findings this week at the Summit on AI Ethics in Athens, Greece.

Read more