A new Google Threat Intelligence Group AI report has revealed a concerning trend in cybersecurity: state-backed hackers and cybercriminals are now using artificial intelligence to enhance their attacks.
Released earlier today, the report shows how adversaries — including groups linked to North Korea, Iran, and China — are experimenting with AI to improve their phishing, reconnaissance, and data exfiltration capabilities.
According to the Google Threat Intelligence Group AI report, hackers are moving beyond simple productivity uses of AI and venturing into novel AI-enabled cyber operations, reshaping how digital threats are evolving worldwide.
AI-Powered Malware and Smarter Phishing Are on the Rise
The Google Threat Intelligence Group AI report highlights how bad actors are weaponizing AI in unexpected ways. Some examples include:
- AI-powered malware that can generate and rewrite its own code to avoid detection by antivirus systems.
- Hackers posing as students or researchers to trick AI models into revealing restricted or sensitive information by bypassing safety guardrails.
- Criminals buying access to underground AI tools designed for phishing campaigns, malware creation, and vulnerability research.
These findings suggest that AI isn’t just a defensive tool for cybersecurity teams anymore — it’s also becoming a powerful weapon in the hands of hackers.
Google’s Countermeasures: Stopping AI Misuse at the Source
In response, Google says it’s taking proactive steps to mitigate AI abuse. The company’s threat analysts have:
- Disabled malicious assets tied to state-sponsored activity.
- Used threat intelligence to strengthen Google’s classifiers and AI models against adversarial attacks.
- Worked with global partners to raise awareness of how AI misuse threatens cybersecurity ecosystems.
A spokesperson for the Google Threat Intelligence Group said the company’s approach is focused on “building AI systems that are secure by design” and ensuring that Google’s own AI technologies can’t be exploited for harm.
AI Security Arms Race Is Just Beginning
The Google Threat Intelligence Group AI report makes it clear that as AI continues to advance, so too do the tactics of those seeking to exploit it.
Experts warn that the cybersecurity industry is now entering a new arms race — one where defending against AI-driven attacks requires AI-powered defenses.
Google’s latest findings reinforce a key takeaway: as artificial intelligence grows smarter, so must our approach to security.
Read the full report on the Google Cloud Threat Intelligence blog.

Don’t miss out on our latest news—follow us for the latest AI news, breakthroughs, and insights that matter.