Google’s threat intelligence unit (GTIG) has published a report on AI-driven cybersecurity threats, including what it claims is the first AI-enabled live threat.
The research shows how threat actors are transitioning from solely using AI for productivity gains to experimenting with more novel capabilities.
The GTIG AI Threat Tracker claims bad actors affiliated with China, North Korea, Russia, and Iran are attempting to use AI for malware execution, social engineering prompts, and to sell AI tooling.
Russian-linked attackers, for example, were claimed to be using a malware known as Promptsteal, identified as the first observed live malware using a large language model (LLM) to produce operational commands in real time.
The networking threat employs the LLM to generate on-demand Windows commands for data exfiltration and system reconnaissance. The dynamically generated commands enable the malware to gather system information and identify sensitive files before transmitting them across the network to an adversary-controlled server.
Another threat, Promptflux, can replicate itself by copying onto removable drives and mapped network shares. Still in an experimental phase, the malware prompts the LLM to modify its own source code and saves the new, stealth version in the Startup folder to maintain infiltration.
“The current state of this malware does not demonstrate an ability to compromise a victim network or device. We have taken action to disable the assets associated with this activity,” assured the researchers.
The report also spotlighted North Korean actor UNC4899 (aka Pukchong), who leveraged Google’s Gemini model for tasks such as coding, exploit research, and tool enhancement. The group’s focus on vulnerability analysis and exploit development suggested it was building capabilities to target edge devices and modern browsers, until GTIG disabled its accounts.
Another threat, meanwhile, was highlighted for how it used AI to stake out less conventional attack surfaces. The unnamed actor exploited Gemini to aid various stages of an intrusion campaign targeting unfamiliar attack environments such as cloud infrastructure, VMware's vSphere suite, and Kubernetes.
Affiliated with the People’s Republic of China (PRC), the adversary had access to Amazon Web Services (AWS) tokens for the platform's EC2 container instances, which it leveraged using info from Gemini.
In another instance, they used Gemini to locate Kubernetes systems and generate commands for enumerating containers and pods.
Billy Leonard, tech lead, Google Threat Intelligence Group, commented that the research showed existing guardrails have driven hackers to models available in the criminal underworld.
“Those tools are unrestricted and can offer a significant advantage to the less advanced. There are several of these available now, and we expect they will lower the barrier to entry for many criminals,” said Leonard.
Comments