Gemini AI - Tool

Threat entity extracted from intelligence sources

Frequency
16
occurrences
First Seen
November 5, 2025
Last Seen
July 6, 2026

Gemini AI is a tool tracked across 10 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 6, 2026.

Related Threat Clusters

  • Google Sues Chinese Cybercrime Network for AI-Powered Phishing Operations

    Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…

    57 articles · Updated June 12, 2026
  • Google API Keys Remain Active for Up to 23 Minutes After Deletion

    Research by Aikido Security reveals that Google API keys can remain active for up to 23 minutes post-deletion, contrary to user expectations of immediate revocation. This delay allows attackers with leaked keys to…

    7 articles · Updated May 21, 2026
  • AI-Driven Smishing Campaign Targets Mobile Users with Phishing Texts

    A large-scale smishing campaign has been reported, utilizing Gemini AI to send fraudulent texts to mobile users. These texts impersonate trusted entities, including toll roads and delivery services, leading victims to…

    2 articles · Updated July 6, 2026
  • PromptFlux Malware Utilizes Gemini AI for Dynamic Code Mutation

    Google has identified a new malware named PromptFlux, which employs a VBScript dropper to dynamically rewrite and mutate its own code in real time using the Gemini API. This malware can adapt its code structure hourly,…

    2 articles · Updated November 5, 2025
  • PromptSpy: First Android Malware Utilizing Generative AI Discovered

    ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and…

    39 articles · Updated February 19, 2026
  • State-Sponsored Hackers Exploit Google's Gemini AI for Cyberattacks

    State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…

    162 articles · Updated February 12, 2026
  • Fraudulent Gemini AI Chatbot Promotes Fake Google Coin Scam

    Scammers have launched a fraudulent website selling a non-existent 'Google Coin' presale, utilizing a fake AI chatbot that impersonates Google's Gemini assistant. This chatbot engages users with promises of high…

    4 articles · Updated February 18, 2026
  • Old Google API Keys Expose Sensitive Data via Gemini Access

    Old Google API keys, previously deemed harmless, now pose a security risk as they can access sensitive data through the Gemini API. Security researchers found that nearly 3,000 keys, originally used for public services,…

    12 articles · Updated February 26, 2026
  • Growing Threat of Sophisticated Phishing Scams Targeting Employees

    Cybercriminals are increasingly using sophisticated phishing tactics to deceive employees through seemingly ordinary emails. These scams, which include fake invoices and urgent messages impersonating executives, are…

    2 articles · Updated January 23, 2026
  • PromptFlux Malware Uses Gemini AI for Real-Time Code Mutation

    Google has identified a new malware named PromptFlux, which employs a VBScript dropper that utilizes the Gemini API to dynamically rewrite and mutate its own code. This malware is designed to evade detection by altering…

    2 articles · Updated November 5, 2025

Recent Intelligence Reports

  • Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and ... — Zimperium · July 6, 2026
  • Google Sues Chinese Cybercrime Operation That Used Gemini AI To Send Scam Texts — Rss.Slashdot · June 12, 2026
  • Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing — Thehackernews · June 12, 2026
  • Google sues the cybercrime ring that turned Gemini AI into a phishing machine — Startupfortune · June 12, 2026
  • Deleted Google API keys keep working for up to 23 minutes, researchers warn — Feeds2.Feedburner · May 22, 2026
  • Google API Keys Expose Private Data Silently Through Gemini — Cybersecuritynews · February 27, 2026
  • Old Google API keys gain new Gemini exposure — Cybernews · February 26, 2026
  • Android Malware Hijacks Google Gemini to Stay Hidden — Infosecurity-Magazine · February 20, 2026

CVSS v3.1 Breakdown