Google Threat Intelligence Reports Artificial Intelligence Is Actively Driving Cyberattack Operations Worldwide

Google Threat Intelligence Group said adversarial AI is moving beyond simple prompting toward more autonomous, agentic activity, changing the speed and economics of cybercrime. John Hultquist said, “we can assume that all threat actors are using AI in some capacity.”
The Russian group UNC5792 has used AI-powered monitoring bots to analyze Telegram messages, identify suspicious activity and turn large volumes of information into structured intelligence reports for Russian authorities.
In addition to writing scripts for password spraying and endpoint fingerprinting, the Russian group SANDWORM has explored AI-assisted obfuscation techniques and projects that connect directly to the Gemini API, indicating efforts to integrate AI more deeply into attack workflows.
Travelers advised that cyber-insurance brokers should expand renewal discussions beyond traditional controls such as multifactor authentication, endpoint detection, backups and patching by asking how clients deploy AI, what business purposes it serves and how they identify related risks.
The LiteLLM vulnerability illustrates that AI security risks extend to conventional infrastructure around models: the proxy can hold multiple provider API keys and carry prompts and model responses containing internal documents, customer records, source code or credentials. Its inclusion in the U.S. Known Exploited Vulnerabilities catalog means federal civilian agencies face a binding remediation deadline.
Google's threat intelligence team said artificial intelligence is now embedded throughout cyberattacks, from spying on messaging apps to writing malware code. Google warned that Russian groups have used AI to monitor Telegram, analyze intelligence and build attack scripts targeting Ukraine. China- and Iran-aligned actors are deploying AI for influence operations. The shift marks a major change: threat actors are moving from simple AI prompting to autonomous, self-directed attacks that work faster and cost less.
The danger extends beyond AI models themselves. A critical flaw in LiteLLM, a widely used proxy that connects to AI systems, was added to the U.S. government's list of actively exploited vulnerabilities. The flaw could expose API keys, internal documents, customer records and sensitive data stored in the proxy. Organizations now face twin risks: they must secure both AI-powered attack techniques and the conventional infrastructure surrounding AI systems.
A Russian group called UNC5792 deployed AI-powered monitoring bots to watch Telegram messages in real time. The bots scan for suspicious activity, then turn massive amounts of raw information into organized intelligence reports for Russian authorities. Google said this represents a shift toward "agentic" AI—systems that work independently without constant human direction.
SANDWORM, another Russian group, has gone further. Beyond writing scripts for password spraying attacks, the group has experimented with AI-assisted code obfuscation to hide malware. Google found evidence that SANDWORM is directly connecting to Google's Gemini API, suggesting plans to weave AI deeper into attack workflows and make them harder to detect.
Ransomware operators are turning to generative AI tools that already sit inside compromised systems. Attackers use these tools to navigate unfamiliar networks, process stolen data faster and speed up their attacks. Google said this tactic is especially dangerous because employees often don't realize attackers can access the same AI systems they use for legitimate work.
The problem forces a hard choice: companies must decide which employees can use AI and which AI tools exist inside their networks. Without clear policies—what Google calls "AI governance"—both employees and attackers gain identical access to powerful automation. Securing these tools is now as critical as patching servers.
LiteLLM is a proxy—essentially a middleman that routes requests between users and AI models. It holds multiple API keys that unlock access to different AI providers. A critical authentication bypass flaw lets attackers skip security checks and steal everything the proxy stores: API keys, model prompts, and model responses containing source code, customer records and passwords.
The U.S. government added the LiteLLM flaw to its Known Exploited Vulnerabilities catalog on Google's urging. Federal civilian agencies now face a binding deadline to patch it. The inclusion signals that AI security risks go far beyond the models themselves—the conventional infrastructure around AI systems is equally dangerous and must be hardened.
Insurance company Travelers is warning cyber-insurance brokers that renewal conversations must expand beyond traditional checklist items: multifactor authentication, endpoint detection, backups and patching. Travelers said brokers need to ask clients three new questions: How do you deploy AI? What business purposes does it serve? How do you identify the risks it creates?
The shift reflects a hard reality: most companies lack clarity on their own AI use. Employees download and use generative AI tools without formal approval. Attackers exploit the same tools to steal data and accelerate breaches. Travelers said cyber-insurance will soon demand explicit AI governance policies before companies can get coverage.
Publishers
22
Articles
46
Reach
68