Gemini API is a tool tracked across 9 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity May 11, 2026.
Gemini API is a component used by the PromptFlux malware to rewrite and hide itself in real time, enabling self-modification for evasion. Its use signals a shift toward AI-assisted, real-time obfuscation in malware campaigns, increasing challenges for detection and defense.
A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…
A three-person development team in Mexico faces financial ruin after a stolen Google Cloud API key resulted in $82,314.44 in unauthorized charges within 48 hours. The key was compromised between February 11 and 12,…
Google has identified a new malware named PromptFlux, which employs a VBScript dropper to dynamically rewrite and mutate its own code in real time using the Gemini API. This malware can adapt its code structure hourly,…
The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…
The discussion around AI Security Operations Centers (SOCs) is evolving, with Gartner's report highlighting the mainstream recognition of AI's potential in enhancing SOC functions. However, critiques emphasize that…
State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…
Old Google API keys, previously deemed harmless, now pose a security risk as they can access sensitive data through the Gemini API. Security researchers found that nearly 3,000 keys, originally used for public services,…
Google's Threat Intelligence Group (GTIG) reports an increase in attempts to extract and replicate AI model logic, with state-backed and financially motivated attackers leveraging generative AI for reconnaissance,…
Google has identified a new malware named PromptFlux, which employs a VBScript dropper that utilizes the Gemini API to dynamically rewrite and mutate its own code. This malware is designed to evade detection by altering…