Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. All Four Major Nation-State Adversaries Now Weaponizing
All Four Major Nation-State Adversaries Now Weaponizing
NEWS

All Four Major Nation-State Adversaries Now Weaponizing

Google reports that APT groups from China, Russia, Iran, and North Korea are all actively using Gemini AI for cyber operations including target...

Dylan H.

News Desk

February 13, 2026
3 min read

AI-Powered Cyber Warfare Is Here

Google has published a landmark report confirming that APT groups from all four major nation-state adversaries — China, Russia, Iran, and North Korea — are actively using Google Gemini AI to enhance their cyber operations. Iran accounts for the largest share of usage, while all four nations have been linked to coordinated defense sector targeting.


Nation-State Usage Breakdown

NationGroups ActivePrimary UsageVolume
IranMultiple IRGC-linked groupsPhishing content, social engineering, target researchLargest share
China20+ groupsLateral movement scripting, vulnerability researchExtensive
North KoreaUNC2970 and othersTarget reconnaissance, profiling technical job rolesSignificant
RussiaMultiple GRU/SVR-linked groupsMalware development assistance, operational planningModerate

How Each Nation Uses Gemini

Iran — Largest Share of Usage

Iranian APT groups use Gemini primarily for:

  • Crafting phishing emails in multiple languages with culturally appropriate lures
  • Social engineering research on specific targets and organizations
  • Technical reconnaissance on target infrastructure
  • Content generation for influence operations and disinformation

China — Lateral Movement Scripting

Over 20 China-backed groups use Gemini for:

  • Writing lateral movement scripts for post-exploitation activities
  • Vulnerability analysis and exploit development assistance
  • Network reconnaissance automation scripts
  • Defense evasion techniques to bypass security controls

North Korea — Target Profiling

North Korea's UNC2970 and related groups use Gemini for:

  • Profiling high-value targets in defense and technology sectors
  • Mapping technical job roles at target organizations
  • Crafting convincing recruiter personas for social engineering
  • Researching cryptocurrency platforms for theft operations

Russia — Operational Support

Russian APT groups use Gemini for:

  • Malware code assistance and debugging
  • Operational planning for cyber campaigns
  • Technical research on target environments
  • Translation and content generation for multi-language operations

Defense Sector Coordination

Google's report notably links all four nations to coordinated cyber operations targeting the defense sector, suggesting either:

  • Independent but parallel targeting of the same high-value defense organizations
  • Intelligence sharing between certain nation-state groups
  • Common target lists derived from publicly available defense contractor information

Implications

AI as Force Multiplier

The weaponization of Gemini demonstrates that AI is now a force multiplier for nation-state cyber operations:

  • Lower barrier to entry — Less skilled operators can produce more sophisticated attacks
  • Speed — Campaign development and target research are dramatically accelerated
  • Scale — AI enables targeting of more organizations simultaneously
  • Quality — Phishing lures and social engineering content are more convincing

Platform Responsibility

Google stated it has:

  • Implemented additional safeguards to detect and block malicious usage
  • Shared indicators with the broader security community
  • Enhanced monitoring for nation-state activity patterns
  • Updated Gemini's safety systems to limit cyber-offensive assistance

Sources

  • WinBuzzer — Nation-State Hackers Weaponizing Gemini AI
  • The Hacker News — Google Links China, Iran, Russia, North Korea to Gemini Abuse

Related Reading

  • Google Disrupts Massive Chinese Espionage Campaign
  • Leaked Documents Reveal China
  • China-Linked UNC3886 Breaches All Four Singapore Telecom
#APT#AI#Gemini#China#Russia#Iran#North Korea#Google#Espionage

Related Articles

Google Disrupts Massive Chinese Espionage Campaign

Google's Threat Intelligence Group dismantles UNC2814, a China-linked operation that deployed a novel backdoor called GRIDTIDE abusing Google Sheets API...

3 min read

Leaked Documents Reveal China's 'Expedition Cloud' Cyber

Technical documents leaked from a malware-infected developer device expose a Chinese military-linked training platform that replicates the critical...

4 min read

Russian-Linked CANFAIL Malware Targets Ukrainian Defense

Google Threat Intelligence Group attributes a previously undocumented JavaScript malware called CANFAIL to a Russian-linked threat actor targeting...

3 min read
Back to all News