Google warns Iran expands AI use in cyberattacks and influence operations

1 hour ago 2



Iran’s cyber operators have found a new favorite tool, and it belongs to Google. The company’s Threat Intelligence Group (GTIG) has identified more than ten Iranian state-backed groups actively exploiting its Gemini AI model to supercharge cyberattacks, build fake online personas, and run disinformation campaigns at scale. Iranian actors now represent the single largest nation-state user demographic of Gemini among threat groups GTIG tracks. Iranian information operations account for roughly 75% of all AI-assisted disinformation efforts the group has observed. What Iran is actually doing with Gemini The most active offender is APT42, also known as GreenBravo, a group widely linked to Iran’s Islamic Revolutionary Guard Corps. APT42 alone is responsible for over 30% of all Iranian APT activity involving Gemini, according to Google’s analysis. Their playbook includes reconnaissance on potential targets, crafting convincing phishing campaigns, writing and debugging code for attack tools, and studying specific techniques to improve their operations. GTIG’s Q3 AI Threat Tracker reported that Iranian actors are now using Gemini to design photorealistic fake identities, complete with count...

Read Entire Article