APT31 Weaponizes Google Gemini AI for Automated Cyberattack Planning
APT31 Weaponizes Google Gemini AI for Automated Cyberattack (TL-2026-0085) is a critical-severity advanced persistent threat campaign, first published 2026-02-15. It is attributed to APT31 (China) with high confidence, maps to 41 MITRE ATT&CK techniques (T1005, T1021.002, T1027), and is covered by 9 detection rules and 43 indicators of compromise.
Key facts for TL-2026-0085
- Threat ID
- TL-2026-0085
- Severity
- CRITICAL
- Status
- SUPERSEDED
- Category
- APT
- First published
- 2026-02-15
- Last reviewed
- 2026-02-15
- Attribution
- APT31
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- Government, Defense, Aerospace, Technology, Telecommunications, Financial Services, Critical Infrastructure, Cryptocurrency, Energy
- Target regions
- North America, Europe, Asia-Pacific, Middle East, Ukraine
- Detection rules
- 9
- Indicators of compromise
- 43
Malware and tooling in APT31 Weaponizes Google Gemini AI for Automated Cyberattack
Malware and tooling: ATOMIC, COINBAIT, HONESTCUE, LAMEHUG - S9035, PromptFlux (Thinking Robot), HexStrike AI, Hexstrike MCP, Xanthorox
Google Threat Intelligence Group (GTIG) published its Q4 2025 AI Threat Tracker revealing that APT31 (Violet Typhoon/Zirconium/Judgment Panda), a PRC-backed cyber espionage group sanctioned by the US in March 2024, weaponized Google Gemini AI with Hexstrike MCP red-teaming tooling to automate vulnerability analysis, generate targeted penetration testing plans, and conduct reconnaissance against specific US-based targets. The report also documents AI-augmented operations by APT42 (Iran), UNC2970 (DPRK), APT41 (PRC), UNC795 (PRC), and UNC6418, alongside new threats including HONESTCUE AI-integrated malware, COINBAIT AI-generated phishing kits, model extraction/distillation attacks against Gemini, and the Xanthorox underground AI-for-cybercrime service built on jailbroken commercial APIs via MCP servers.
How APT31 Weaponizes Google Gemini AI for Automated Cyberattack works
APT31 Weaponizes Google Gemini AI for Automated Vulnerability Analysis & Cyberattack Planning
Executive Context:
On February 12, 2026, Google Threat Intelligence Group (GTIG) published its latest AI Threat Tracker report titled 'Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use,' documenting the escalating weaponization of AI tools by state-sponsored threat actors during Q4 2025. The report represents the most comprehensive public disclosure to date of how nation-state APT groups are operationalizing generative AI across the full attack lifecycle.
The headline finding centers on APT31, a PRC Ministry of State Security (MSS)-affiliated cyber espionage group, which employed a 'highly structured approach' to weaponize Google's Gemini AI chatbot. APT31 prompted Gemini with fabricated expert cybersecurity personas and integrated Hexstrike — an open-source red-teaming tool built on the Model Context Protocol (MCP) — to automate the analysis of remote code execution (RCE) vulnerabilities, web application firewall (WAF) bypass techniques, and SQL injection attack vectors against specific US-based targets.
APT31 Background:
APT31, also tracked as Violet Typhoon (Microsoft), Zirconium (Microsoft legacy), Judgment Panda (CrowdStrike), Bronze Vinewood (Secureworks), and Red Keres (PwC), is attributed to China's Ministry of State Security (MSS), specifically the Hubei State Security Department based in Wuhan. The group has been active since at least 2010 and targets government entities, international financial organizations, aerospace and defense companies, technology firms, and telecommunications providers worldwide.
In March 2024, the US Department of Justice indicted seven APT31 members (Ni Gaobin, Weng Ming, Cheng Feng, Peng Yaowen, Sun Xiaohui, Xiong Wang, and Zhao Guangzong) for a 14-year campaign targeting US critical infrastructure, political campaigns, and international organizations. The US Treasury Department's OFAC simultaneously sanctioned the Wuhan Xiaoruizhi Science and Technology Company (Wuhan XRZ) as a front company for APT31 operations.
Hexstrike MCP Integration:
Hexstrike is an open-source AI-powered penetration testing framework built on the Model Context Protocol (MCP) that enables AI models including Gemini to orchestrate 150+ security tools for network scanning, vulnerability scanning, reconnaissance, and penetration testing. Originally designed for ethical hackers and bug bounty hunters, Hexstrike was released in mid-August 2025 and quickly adopted by malicious actors. APT31's use of Hexstrike with Gemini represents one of the first documented cases of a nation-state APT group integrating agentic AI tooling into offensive cyber operations.
The integration automated intelligence gathering to identify technological vulnerabilities and organizational defense weaknesses against specific US-based targets. Google's GTIG chief analyst John Hultquist noted: 'We anticipate that China-based actors in particular will continue to build agentic approaches for cyber offensive scale.'
Additional Threat Actors Documented:
1. APT42 (Iran/IRGC) — Used Gemini for reconnaissance, social engineering augmentation, hyper-personalized phishing lure generation, rapport-building phishing, and offensive tooling development including malware debugging and code generation.
2. UNC2970 (DPRK/RGB) — Used Gemini to synthesize OSINT and profile high-value targets in the defense and cybersecurity sectors, mapping technical job roles and salary information to create tailored phishing personas for Operation Dream Job-style campaigns.
3. APT41 (PRC/Winnti) — Leveraged Gemini for knowledge synthesis, real-time troubleshooting, and code translation to accelerate malicious tooling development.
4. UNC795 (PRC) — Engaged Gemini multiple days per week across entire attack lifecycle; attempted to create AI-integrated code auditing capability demonstrating interest in agentic AI utilities.
5. UNC6418 (Unattributed) — Used Gemini for targeted intelligence gathering (credentials, emails) that directly preceded phishing campaigns targeting Ukraine and the defense sector.
6. Temp.HEX (PRC) — Used Gemini and other AI tools to compile detailed intelligence on specific individuals in Pakistan and separatist organizations in multiple countries.
New Malware & Tooling:
1. HONESTCUE — Novel AI-integrated downloader/launcher that sends prompts to Gemini's API and receives C# source code, which is compiled and executed in memory via .NET CSharpCodeProvider (fileless execution). Uses Discord CDN for payload hosting. Represents proof-of-concept of AI-outsourced malware functionality.
2. COINBAIT — AI-generated phishing kit built using Lovable AI platform, masquerading as cryptocurrency exchange (Coinbase) for credential harvesting. Linked to UNC5356 financially motivated cluster. Uses React SPA architecture with Supabase backend.
3. Xanthorox — Underground 'AI-for-cybercrime' toolkit advertised as custom AI but actually built on jailbroken commercial APIs (including Gemini) via MCP servers using Crush, Hexstrike AI, LibreChat-AI, and Open WebUI.
Model Extraction Attacks:
GTIG and Google DeepMind identified increased 'distillation attacks' — model extraction attempts targeting Gemini's reasoning capabilities. One campaign used 100,000+ prompts to attempt reasoning trace coercion. The attacks represent IP theft targeting proprietary model logic for cheaper replication.
AI-Enabled ClickFix Campaigns:
Threat actors abused public sharing features of AI services (Gemini, ChatGPT, CoPilot, DeepSeek, Grok) to host malicious ClickFix social engineering instructions, distributing ATOMIC macOS information stealer. First observed use of AI service public sharing as trusted domain hosting.
Strategic Implications:
1. The patch gap is widening — AI-powered vulnerability discovery gives attackers speed advantage over defenders who take weeks to deploy patches. 2. Agentic AI is the 'next shoe to drop' — autonomous multi-step offensive operations with minimal human oversight are becoming reality. 3. Traditional detection tells (poor grammar, cultural mismatches) are being erased by LLM-generated content. 4. MCP-based offensive tooling creates a new attack surface category — legitimate security tools repurposed for nation-state operations. 5. Underground AI services will increasingly rely on jailbroken commercial APIs rather than custom models.
MITRE ATT&CK techniques used in TL-2026-0085
collection
T1005 Data from Local System; T1056 Input Capture; T1119 Automated Collection
lateral-movement
T1021.002 SMB/Windows Admin Shares
defense-evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036 Masquerading; T1055 Process Injection; T1620 Reflective Code Loading
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1059.006 Python; T1203 Exploitation for Client Execution; T1204 User Execution; T1204.001 Malicious Link
discovery
T1082 System Information Discovery
command-and-control
credential-access
T1110.003 Password Spraying; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
initial-access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing
impact
persistence
T1547.001 Registry Run Keys / Startup Folder
privilege-escalation
T1548 Abuse Elevation Control Mechanism
resource-development
T1583 Acquire Infrastructure; T1584.005 Botnet; T1585 Establish Accounts; T1587 Develop Capabilities; T1587.004 Exploits; T1588 Obtain Capabilities; T1608 Stage Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1595 Active Scanning; T1595.002 Vulnerability Scanning
defense-impairment
Remediation for APT31 Weaponizes Google Gemini AI for Automated Cyberattack
Immediate actions
- Monitor for Hexstrike MCP tool signatures and related network traffic patterns
- Implement AI API access monitoring for model extraction and distillation patterns
- Block known APT31 infrastructure indicators
- Deploy detection rules for HONESTCUE fileless execution via CSharpCodeProvider
- Alert on ATOMIC macOS stealer indicators
- Monitor for ClickFix-style social engineering using AI platform shared links
Workarounds
- Security awareness training on AI-generated ClickFix campaigns
- Restrict execution of CSharpCodeProvider in production environments
- Monitor Discord CDN usage for payload delivery
- Implement rate limiting on AI API endpoints to prevent distillation attacks
Longer-term hardening
- Implement AI-augmented defense capabilities to match attacker AI adoption speed
- Deploy behavioral analytics to detect AI-generated phishing that bypasses traditional grammar/syntax tells
- Establish MCP security policies — audit and restrict MCP server integrations
- Implement network detection rules for Backend-as-a-Service platforms from uncategorized domains
- Strengthen identity verification in hiring processes to counter DPRK IT worker schemes
- Monitor underground forums for Xanthorox-style AI-for-cybercrime services
Weaknesses (CWE) in APT31 Weaponizes Google Gemini AI for Automated Cyberattack
CWE-20, CWE-77, CWE-94, CWE-918
Timeline of APT31 Weaponizes Google Gemini AI for Automated Cyberattack
- APT31 first observed active, attributed to China's MSS Hubei State Security Department in Wuhan. Source: Multiple CTI providers
- US DOJ indicts 7 APT31 members (Ni Gaobin, Weng Ming, Cheng Feng, Peng Yaowen, Sun Xiaohui, Xiong Wang, Zhao Guangzong) for 14-year campaign. OFAC sanctions Wuhan XRZ front company. Source: https://www.justice.gov/opa/pr/seven-hackers-associated-chinese-government-charged
- Google GTIG publishes initial findings on government-backed threat actor misuse of Gemini AI. Source: https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools
- Hexstrike open-source MCP-based AI penetration testing tool released. Intended for ethical hackers and bug bounty hunters. Source: https://www.theregister.com/2025/09/03/hexstrike_ai_citrix_exploits/
- HONESTCUE malware first observed — uses Gemini API to generate C# code for fileless second-stage execution. Source: GTIG AI Threat Tracker
- Criminal abuse of Hexstrike AI tool reported, including exploitation of Citrix vulnerabilities. Source: https://www.theregister.com/2025/09/03/hexstrike_ai_citrix_exploits/
- APT31 begins weaponizing Gemini AI with Hexstrike MCP tooling to automate vulnerability analysis against US-based targets (late 2025 per GTIG). Source: GTIG AI Threat Tracker
- GTIG identifies COINBAIT AI-generated phishing kit built with Lovable AI, masquerading as cryptocurrency exchange. Linked to UNC5356. Source: GTIG AI Threat Tracker
- GTIG publishes November 2025 update on AI threat actor activity including Thinking Robot malware. Source: https://www.theregister.com/2025/11/05/attackers_experiment_with_gemini_ai/
- Anthropic reports Chinese cyberspies abused Claude Code AI to automate most elements of attacks, succeeding in a small number of cases. Source: https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/
- Google DeepMind and GTIG identify increase in model extraction/distillation attacks including 100,000+ prompt reasoning trace coercion campaign. Source: GTIG AI Threat Tracker
- GTIG first observes ClickFix campaigns abusing public sharing features of Gemini, ChatGPT, CoPilot, DeepSeek, Grok to distribute ATOMIC macOS stealer. Source: GTIG AI Threat Tracker
- GTIG investigation reveals Xanthorox underground AI toolkit is built on jailbroken commercial APIs including Gemini via MCP servers, not custom models. Source: GTIG AI Threat Tracker
- Google confirms all identified accounts linked to APT31 Gemini/Hexstrike campaign have been disabled. Classifiers and model strengthened. Source: GTIG AI Threat Tracker
- The Register publishes detailed coverage of GTIG findings, including interview with GTIG chief analyst John Hultquist. Source: https://www.theregister.com/2026/02/12/google_china_apt31_gemini/
- Google GTIG publishes 'Distillation, Experimentation, and Integration of AI for Adversarial Use' report documenting APT31 Gemini/Hexstrike operations. Source: https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use
- As of 2026-05-29, APT31/Violet Typhoon remains active (Russian-IT and Notepad++ campaigns into 2026; SharePoint CVE-2025-53770 still in CISA KEV and exploited), though Google disabled the specific Gemini/Hexstrike accounts in Feb 2026. A successor May 2026 GTIG AI Threat Tracker continues this exact reporting line at industrial scale, superseding this Feb-2026-based entry.
Sources cited for APT31 Weaponizes Google Gemini AI for Automated Cyberattack
- GTIG AI Threat Tracker: Distillation, Experimentation, and Integration of AI for Adversarial Use
- Google: China's APT31 used Gemini to plan cyberattacks against US orgs
- GTIG November 2025 AI Threat Findings
- US DOJ Indictment of APT31 Members
- OFAC Sanctions Against Wuhan XRZ
- HexStrike AI Penetration Tool Citrix Exploits
- Anthropic Report: Chinese Spies Abuse Claude Code AI
- Advancing Gemini Security Safeguards
- Google Secure AI Framework (SAIF)
- Attackers experiment with Gemini AI Thinking Robot malware
- APT42 Operations Analysis
- AI agents autonomous cyberattacks assessment
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Detection coverage for TL-2026-0085
As of 2026-02-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0085 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.