Back Sdxcentral Google report exposes ways threat actors use AI to speed up attacks
Findings show that the underground marketplace for illicit AI tools has matured, lowering the barrier for less sophisticated actors
Google Threat Intelligence Group (GTIG) reported that threat actors have been increasingly integrating AI to expedite attacks, increasing their productivity in investigation, social engineering, and malware development.
The company released these recent revelations in its new quarterly report on the advances in threat actor use of AI tools, an update to its findings published in November last year.
For government-backed attackers, large language models (LLMs) have emerged as essential tools for technical research, targeting, and the rapid generation of nuanced phishing lures.
The report noted steps the teams have taken to thwart malicious activity, including Google detecting, disrupting, and mitigating model extraction activity.
“While we have not observed direct attacks on frontier models or generative AI products from advanced persistent threat (APT) actors, we observed and mitigated frequent model extraction attacks from private sector entities all over the world and researchers seeking to clone proprietary logic,” the authors of the report said.
Threat actors from North Korea, Iran, China, and Russia operationalized AI in late 2025 focusing on new and emerging elements, including AI-augmented operations where groups were streamlining reconnaissance or investigation and rapport-building phishing, and agentic AI, where attackers were beginning to show interest in building agentic AI capabilities to support malware and tooling development.
Another example is the Underground "Jailbreak" Ecosystem – emerging malicious services like Xanthorox that claim to be independent models while relying on jailbroken commercial APIs and open-source Model Context Protocol (MCP) servers .
In September 2025, GTIG observed malware samples using Gemini's API to outsource functionality generation. In this case, the adversary’s incorporation of AI was likely designed to support a multi-layered approach to obfuscation by undermining traditional network-based detection and static analysis.
“However, rather than leveraging an LLM to update itself, [the bad actor] calls the Gemini API to generate code that operates the 'stage two' functionality, which downloads and executes another piece of malware,” the report’s authors said. The threat actor also used content delivery networks (CDNs) like Discord CDN to host the final payloads.
The new findings build on GTIG’s November report, which recorded the first use of "Just-in-Time" AI in malware – malware families that use LLM tools dynamically to generate malicious scripts, obfuscate their own code to evade detection, and leverage AI models to create malicious functions on demand, rather than hard-coding them into the malware.
Google Threat Intelligence’s findings also concluded that the underground marketplace for illicit AI tools matured in 2025, lowering the barrier to entry for less sophisticated actors.
In a similar development, SDxCentral recently uncovered that AI was sharing security evasion tips on a ' for agentic AI' forum run by agents, with proxy bots seen sharing workarounds for web scraping.
The discovery, made on Moltbook, the so-called for AI agents, came as concern rises with OpenClaw-style AI ecosystems, which enable AI agents to execute, coordinate, and delegate tasks to other agents automatically.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
