Gemini API - Tool

Threat entity extracted from intelligence sources

Frequency
21
occurrences
First Seen
November 5, 2025
Last Seen
May 11, 2026

Gemini API is a tool tracked across 9 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity May 11, 2026.

Overview

Gemini API is a component used by the PromptFlux malware to rewrite and hide itself in real time, enabling self-modification for evasion. Its use signals a shift toward AI-assisted, real-time obfuscation in malware campaigns, increasing challenges for detection and defense.

Related Threat Clusters

  • Google API Key Vulnerability Exposes Gemini AI Access in Android Apps

    A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…

    2 articles · Updated April 10, 2026
  • Stolen Gemini API Key Leads to $82K in Unauthorized Charges

    A three-person development team in Mexico faces financial ruin after a stolen Google Cloud API key resulted in $82,314.44 in unauthorized charges within 48 hours. The key was compromised between February 11 and 12,…

    3 articles · Updated March 4, 2026
  • PromptFlux Malware Utilizes Gemini AI for Dynamic Code Mutation

    Google has identified a new malware named PromptFlux, which employs a VBScript dropper to dynamically rewrite and mutate its own code in real time using the Gemini API. This malware can adapt its code structure hourly,…

    2 articles · Updated November 5, 2025
  • Google GTIG Reports Shift in AI Misuse by Cyber Adversaries

    The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…

    3 articles · Updated November 5, 2025
  • Debate on AI SOC Agents and Security Outcomes

    The discussion around AI Security Operations Centers (SOCs) is evolving, with Gartner's report highlighting the mainstream recognition of AI's potential in enhancing SOC functions. However, critiques emphasize that…

    52 articles · Updated November 16, 2025
  • State-Sponsored Hackers Exploit Google's Gemini AI for Cyberattacks

    State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…

    162 articles · Updated February 12, 2026
  • Old Google API Keys Expose Sensitive Data via Gemini Access

    Old Google API keys, previously deemed harmless, now pose a security risk as they can access sensitive data through the Gemini API. Security researchers found that nearly 3,000 keys, originally used for public services,…

    12 articles · Updated February 26, 2026
  • Rise in AI Model Theft and Misuse by Threat Actors

    Google's Threat Intelligence Group (GTIG) reports an increase in attempts to extract and replicate AI model logic, with state-backed and financially motivated attackers leveraging generative AI for reconnaissance,…

    13 articles · Updated February 12, 2026
  • PromptFlux Malware Uses Gemini AI for Real-Time Code Mutation

    Google has identified a new malware named PromptFlux, which employs a VBScript dropper that utilizes the Gemini API to dynamically rewrite and mutate its own code. This malware is designed to evade detection by altering…

    2 articles · Updated November 5, 2025

Recent Intelligence Reports

  • Google warns: for the first time, hackers used AI to find and exploit a security flaw — Insurancebusinessmag · May 11, 2026
  • Google warns: for the first time, hackers used AI to find and exploit a security flaw — Insurancebusinessmag · May 11, 2026
  • Google warns: for the first time, hackers used AI to find and exploit a security flaw — Insurancebusinessmag · May 11, 2026
  • Google warns: for the first time, hackers used AI to find and exploit a security flaw — Insurancebusinessmag · May 11, 2026
  • Google warns: for the first time, hackers used AI to find and exploit a security flaw — Insurancebusinessmag · May 11, 2026
  • Google API Keys Quietly Gain Access to Gemini on Android Devices — Infosecurity-Magazine · April 8, 2026
  • Dev stunned by $82K Gemini API key bill after theft • The Register — Theregister · March 4, 2026
  • Your Google Maps Key Might Now Be a Security Risk — Here's Why — C3.Unu.Edu · February 27, 2026

CVSS v3.1 Breakdown