Google says it blocked AI-assisted cyberattack plot, warns of North Korean hacking activity

Google says it blocked AI-assisted cyberattack plot, warns of North Korean hacking activity

Google says it blocked AI-assisted cyberattack plot, warns of North Korean hacking activity

https://m.ajupress.com/amp/20260512133139288

Publish Date: 2026-05-12 00:55:00

Source Domain: m.ajupress.com

A Google logo is seen at a company research facility in Mountain View, California, U.S., May 13, 2025. Reuters-Yonhap

SEOUL, May 12 (AJP) – Google claimed it had preemptively blocked hackers who were preparing large-scale cyberattacks using artificial intelligence and identified North Korean state-linked hacking activities leveraging AI to refine cyber operations.

According to its report published on the Cloud Security blog, Google’s Threat Intelligence Group (GTIG) uncovered a threat actor believed to have used AI in preparations for a “zero-day” attack campaign. 

Google said the actor appeared to be planning broad operations, but the company’s early intervention likely prevented the attacks from being executed.

A zero-day attack exploits previously unknown software vulnerabilities before developers can issue security patches, making such intrusions especially difficult to defend against.

The disclosure adds to mounting concerns in the cybersecurity industry that rapid advances in AI-assisted vulnerability detection could accelerate the discovery and weaponization of software flaws.

According to the report, the attackers sought to exploit vulnerabilities to bypass two-factor authentication systems. Google stressed there was no evidence its own AI model, Gemini, had been used in the operation.

While Google did not identify the actor behind the attempted attacks, it separately warned that state-backed hacking groups linked to China and North Korea are showing “particular interest” in applying AI to cyber operations.

The company said such groups are adopting increasingly sophisticated AI-assisted techniques for vulnerability discovery and exploitation, including integrating specialized, high-quality security datasets into their workflows.
 

This image is generated by NotebookLM.

Google specifically highlighted North Korean hacking group APT45, saying there were indications the group had conducted automated research by…

Source