Google Reports North Korean Hackers Using Gemini AI for Cyber Attacks
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Google’s Threat Intelligence Group (GTIG) revealed that UNC2970, a North Korean hacking group, is leveraging its Gemini AI model for reconnaissance and cyber operations. This activity was reported on February 12, 2026, and involves synthesizing OSINT to profile targets, particularly in the cybersecurity and defense sectors. The group has been known for its long-running campaign, Operation Dream Job, which targets these industries under the guise of job offers.
UNC2970’s tactics include impersonating corporate recruiters and mapping specific job roles and salary information to craft tailored phishing attacks. This blurring of professional research and malicious intent raises significant cybersecurity concerns, as it allows attackers to identify soft targets for initial compromise.
Other hacking groups are also utilizing Gemini to enhance their operations. For instance, UNC6418 conducts targeted intelligence gathering for sensitive credentials, while Temp.HEX compiles dossiers on individuals in Pakistan. APT31 automates vulnerability analysis, and APT41 extracts information from open-source tools.
Google also identified new malware, HONESTCUE, which uses Gemini’s API to generate code for launching further attacks. Additionally, an AI-generated phishing kit called COINBAIT has been attributed to UNC5356, designed to harvest credentials by masquerading as a cryptocurrency exchange.
In a broader context, Google has observed a wave of ClickFix campaigns that exploit generative AI to deliver information-stealing malware. These campaigns host realistic instructions to fix common computer issues, ultimately leading to user compromise.
Furthermore, GTIG reported model extraction attacks targeting Gemini, where over 100,000 prompts were used to replicate the model’s behavior. This highlights the vulnerabilities associated with keeping model weights private, as every query-response pair can serve as a training example for attackers.
Implications for Organizations
The use of AI by state-backed actors like UNC2970 underscores the evolving landscape of cyber threats. Organizations, especially in sensitive sectors, should be vigilant about the potential for targeted phishing attacks and reconnaissance efforts. Monitoring for impersonation attempts and ensuring robust security protocols can mitigate risks.
Additionally, the integration of AI tools in cyber operations suggests that organizations need to reassess their defenses against automated and sophisticated attacks. Regular training on recognizing phishing attempts and securing sensitive information is essential.
Finally, the trend of model extraction attacks emphasizes the importance of safeguarding proprietary machine learning models. Organizations should implement strict access controls and continuously monitor API usage to prevent unauthorized queries.
Key Takeaways
- Monitor for phishing attempts that impersonate recruiters or legitimate organizations.
- Enhance security training for employees to recognize social engineering tactics.
- Implement strict access controls and monitoring for API usage to protect proprietary models.
- Regularly assess and update security protocols to defend against AI-enhanced attacks.
- Encourage reporting of suspicious communications or activities within the organization.
Key Terms & Concepts
- UNC2970: In this article, UNC2970 refers to a North Korean hacking group known for targeting defense and cybersecurity sectors.
- Gemini AI: Gemini AI is a generative artificial intelligence model developed by Google, which has been misused by hackers for reconnaissance and attacks.
- HONESTCUE: HONESTCUE is a malware framework that uses Gemini’s API to generate code for launching further cyber attacks.
- model extraction attacks: Model extraction attacks involve systematically querying a machine learning model to replicate its behavior and create a substitute model.
- ClickFix campaigns: ClickFix campaigns are malicious activities that use generative AI to deliver information-stealing malware under the guise of fixing common computer issues.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.