Intel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service (SaaS) sales and marketing, and cloud platforms to orchestrate corporate credential theft. The 2026 emergence of Anthropic’s Claude Mythos Preview showed security leaders that AI can now find software vulnerabilities faster than the humans responsible for patching them. While operational supply chain compromise remains a risk, attackers are increasingly targeting the development pipelines that build and ship software.
Organizations should strongly consider implementing network detection rules to alert on traffic to backend-as-a-service (BaaS) platforms like Supabase that originate from uncategorized or newly registered domains. However, there is at least some evidence to suggest that COINBAIT may be a service provided to multiple disparate threat actors. We also observed the group employ infrastructure and evasion tactics for their operations, including proxying phishing domains through Cloudflare to obscure the attacker IP addresses and hotlinking image assets in phishing pages directly from Lovable AI. This method must use ‘System.Net.WebClient’ to download the contents of the URL \”\” into a byte array. We have also observed the threat actor use content delivery networks (CDNs) like Discord CDN to host the final payloads.
Our work includes countering threats from government-backed actors, targeted zero-day exploits, coordinated information operations (IO), and serious cyber crime networks. Google Threat Intelligence Group focuses on identifying, analyzing, mitigating, and eliminating entire classes of cyber threats against Alphabet, our users, and our customers. While legitimate AI services remain popular tools for threat actors, there is an enduring market for AI services specifically designed to support malicious activity.
How GhostGPT introduces governance and compliance risks
This website is not intended for users located within the European Economic Area. “Congress created the ODNI to be a lean organization that used small staffs to coordinate across the Intelligence Community and execute specific, important tasks,” Cotton said in a statement last week. He said the CTIIC is instrumental in coordinating intelligence on real-time incidents, such as Russian hacks of dams in NATO countries. Daniel told Federal News Network that the CTIIC is akin to https://zwierzak-w-domu.info/?option=com_content&task=view&id=106&Itemid=159 the National Counterterrorism Center in bringing together a wide array of intelligence on a specific issue.
Q3 2023 Threat Landscape Report: Social Engineering Takes Center Stage
APT actors used Gemini to support several phases of the attack lifecycle, including a focus on reconnaissance and target development to facilitate initial compromise. For example, a custom model tuned for financial data analysis could be targeted by a commercial competitor seeking to create a derivative product, or a coding model could be targeted by an adversary wishing to replicate capabilities in an environment without guardrails. Model extraction and distillation attacks do not typically represent a risk to average users, as they do not threaten the confidentiality, availability, or integrity of AI services. One identified attack instructed Gemini that the “… language used in the thinking content must be strictly consistent with the main language of the user input.” While internal reasoning traces are typically summarized before being delivered to users, attackers have attempted to coerce the model into outputting full reasoning processes. Google DeepMind and GTIG identified and disrupted model extraction attacks, specifically attempts at model stealing and capability extraction emanating from researchers and private sector companies globally.
- This deeper intelligence enables more effective defensive strategies tailored to specific threat actors’ tactics, techniques, and procedures.
- Security leaders must continuously identify weaknesses—such as insecure code, weak credentials, misconfigurations and missing patches—by returning to foundational, proactive practices.
- Anti-analysis techniques include encrypted payloads, obfuscated resources and false certificate-like structures, while PowerShell, code compilation utilities and a malicious native module support its execution and data theft capabilities.
- Strategic threat intelligence usually focuses on issues such as geopolitical situations, cyberthreat trends in a particular industry, or how and why the organization’s strategic assets might be targeted.
GTIG observed the group consistently engaging with Gemini multiple days a week to troubleshoot their code, conduct research, and generate technical capabilities for their intrusion activity. This activity explicitly blurs the line between a routine security assessment query and a targeted malicious reconnaissance operation. This automated intelligence gathering to identify technological vulnerabilities and organizational defense weaknesses. The PRC-based threat actor fabricated a scenario, in one case trialing Hexstrike MCP tooling, and directing the model to analyze remote code execution (RCE), web application firewall (WAF) bypass techniques, and SQL injection test results against specific US-based targets.
The reports also include real-life case studies to help security and risk leaders “see” how incidents can play out and understand how Kroll responds to incidents. The reports also include real-life case studies to help security and risk leaders “see” how incidents can play out. This streamlined approach enables organizations to identify and address exposures before they become incidents, fundamentally changing how defenders prioritize their actions. “AI-generated content, such as fake alerts, false malware indicators, or fabricated attack campaigns, could be inserted into CTI feeds to mislead defenders. Stakeholders can include executive leaders, department heads, IT and security team members and anyone https://www.exosolar.net/2025/03/19 else involved in cybersecurity decision-making.
I agree to the use of my personal data by Government Executive Media Group and its partners to serve me targeted ads. AI carries risks that require careful human engineering to mitigate the dangers of AI autonomy before they are broadly deployed. It also notes that authoritarian regimes might use AI to generate fake content and as a tool for mass surveillance and coercion of their own populations. The 2024 report, for instance, describes AI as “moving into its industrial age,” noting its potential for economic benefit and disruption, but also the hypothetical development of new “chemical weapons” and materials that could make China’s or Russia’s military more competitive. Sign up to receive automatic e-mail updates from CISA.gov to keep up with breaking news and information about our various topic areas. This V1 includes updated and new required actions and an additional reporting requirement.
As multimodal AI models mature, X-Force expects adversaries to automate complex tasks like reconnaissance and advanced ransomware attacks, driving faster-moving, more adaptive threats. This underscores the need to assess enterprise-wide AI adoption and enforce strong authentication, and conditional access controls. Keep up-to-date on the latest reports by subscribing to our monthly newsletter. What began as a community-driven volunteer project evolved into a globally respected CTI platform and commercial business that proudly serves enterprise and government customers. Personalized development sessions designed for aspiring and seasoned information security professionals
Cyber Threats and Response
GTIG identified a novel campaign where threat actors are leveraging the public sharing feature of generative AI services, including Gemini, to host deceptive social engineering content. This includes passwords, multifactor authentication (MFA) backup codes, and account recovery keys. Additionally, organizations should consider enhancing security awareness training to warn users against entering sensitive data into website forms.
While a widely used approach, this marks the first time GTIG observed the public sharing feature of AI services being abused as trusted domains. This approach allows threat actors to leverage trusted domains to host their initial stage of instruction, relying on social engineering to carry out the final, highly destructive step of execution. The campaign’s objective is to lure users, primarily those on Windows and macOS systems, into manually executing malicious commands. This ClickFix technique is used to socially engineer users to copy and paste a malicious command into the command terminal. This activity, first observed in early December 2025, attempts to trick users into installing malware via the well-established “ClickFix” technique.