Gemini AI is a tool tracked across 10 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 6, 2026.
Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…
Research by Aikido Security reveals that Google API keys can remain active for up to 23 minutes post-deletion, contrary to user expectations of immediate revocation. This delay allows attackers with leaked keys to…
A large-scale smishing campaign has been reported, utilizing Gemini AI to send fraudulent texts to mobile users. These texts impersonate trusted entities, including toll roads and delivery services, leading victims to…
Google has identified a new malware named PromptFlux, which employs a VBScript dropper to dynamically rewrite and mutate its own code in real time using the Gemini API. This malware can adapt its code structure hourly,…
ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and…
State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…
Scammers have launched a fraudulent website selling a non-existent 'Google Coin' presale, utilizing a fake AI chatbot that impersonates Google's Gemini assistant. This chatbot engages users with promises of high…
Old Google API keys, previously deemed harmless, now pose a security risk as they can access sensitive data through the Gemini API. Security researchers found that nearly 3,000 keys, originally used for public services,…
Cybercriminals are increasingly using sophisticated phishing tactics to deceive employees through seemingly ordinary emails. These scams, which include fake invoices and urgent messages impersonating executives, are…
Google has identified a new malware named PromptFlux, which employs a VBScript dropper that utilizes the Gemini API to dynamically rewrite and mutate its own code. This malware is designed to evade detection by altering…