State-Sponsored Hackers Leverage AI Tools for Cyberattacks
- Google’s Threat Intelligence Group reports state-sponsored hackers are using AI tools like Gemini to accelerate cyberattacks.
- The report highlights increased model extraction attempts, a form of intellectual property theft.
- Countries such as North Korea, Iran, China, and Russia are identified as utilizing large language models for phishing and reconnaissance.
- AI tools enable hyper-personalized phishing scams by improving the accuracy and speed of victim profiling.
- There is growing interest in agentic AI, which can autonomously support tasks like malware development.
Google’s report underscores the increasing use of AI by state-backed actors to enhance cyberattack capabilities, focusing on technical research and phishing lures. The use of large language models allows these actors to bypass traditional indicators of phishing attempts through hyper-personalization.
Despite the increased risk posed by AI tools in cyber threats, Google notes that no breakthrough capabilities have been achieved yet, but there is a notable rise in tool usage and associated risks (Source).