Google Threat Intelligence Group reports state-sponsored misuse of Gemini
Iran accounted for three-quarters of observed information-operations use; Google said no actor achieved a novel capability and jailbreak attempts largely failed.
- Security & misuse
- Notable
Google’s Threat Intelligence Group published its first report on government-linked misuse of Gemini, tracking activity from more than 20 China-backed groups, nine linked to North Korea, and smaller numbers tied to Iran and Russia, alongside separate information-operations actors.
Most use was for productivity, not novel attacks. State-linked hacking groups used Gemini across the attack lifecycle — reconnaissance on targets, rewriting and translating malware code, researching vulnerabilities, and evading detection tools — rather than to develop capabilities they did not already have. North Korean actors used it partly to support the country’s clandestine IT-worker scheme, researching job applications and cover personas. Iran was the heaviest user among information-operations accounts, responsible for roughly three-quarters of the content-generation activity Google observed, mostly drafting and localising political content; China’s DRAGONBRIDGE network used it to research US politics and Taiwan. Attempts at prompt injection or jailbreaking Gemini were, Google said, largely unsophisticated, drew on publicly circulating techniques, and did not succeed against the model’s safeguards.
The report’s stated conclusion pushed back on characterising generative AI as a breakthrough enabler for threat actors: “current LLMs on their own are unlikely to enable breakthrough capabilities for threat actors,” it said, comparing Gemini’s role to existing offensive tools such as Metasploit — useful for speed and volume, not for doing something attackers could not already do by other means.
The report was the first in a recurring series; a November 2025 follow-up reported North Korean group PUKCHONG using Gemini for malware research, part of a broader pattern of continued, incremental state use rather than a step change in what AI let attackers achieve.