State-Backed Hackers Turn to AI Agents for Cyber Espionage, Google Warns

State-backed groups linked to Russia, China, Iran and North Korea are increasingly using AI to accelerate cyber espionage targeting governments, defence companies and international organisations.

State-Backed Hackers Turn to AI Agents for Cyber Espionage, Google Warns
Photo: Illustration. Credit: AD

State-backed threat groups linked to Russia, China, Iran and North Korea are increasingly integrating artificial intelligence into cyber-espionage operations, according to new findings from Google Threat Intelligence Group (GTIG).

Google said adversaries are progressing from basic chatbot prompts toward agentic workflows and AI-enabled automation. These tools are being used to accelerate target identification, vulnerability research, spear-phishing, malware development, credential theft and the processing of stolen information.

The development could significantly reduce the time available for governments and defence companies to detect and contain intrusions.

Russian groups automate operations against Ukraine

SANDWORM RELIC, Google’s designation for the Russian cyber-espionage group widely known as Sandworm or APT44, has reportedly used Gemini to support intelligence gathering, social engineering and workflow automation in operations targeting Ukraine.

The group used AI to develop asynchronous password-spraying tools, profile compromised systems and automate the routing of malicious infrastructure through proxies.

Google also observed Russian-linked operators incorporating AI-related domains into phishing infrastructure.

Chinese actors target governments and international organisations

RAVINE CASTLE, a China-linked cyber-espionage group previously known as APT24, used AI to research foreign ministries and international organisations ahead of social-engineering operations.

The group reportedly explored methods for compromising virtualisation infrastructure, elevating access inside Active Directory environments and transforming stolen data into structured intelligence reports.

Google said the actors also investigated ways to distribute leaked information anonymously to journalists and social-media accounts, connecting cyber espionage with broader influence operations.

Aerospace and defence organisations remain targets

North Korean threat clusters have used AI to profile aerospace and defence organisations and produce fabricated résumés, job descriptions and recruiter identities.

Such activity reflects the continued use of fraudulent IT workers and social-engineering campaigns to obtain employment, access corporate systems and generate revenue for sanctioned programmes.

Iran-linked CALANQUE ION, previously tracked as APT42, has meanwhile used generative AI to identify individuals and email addresses, produce localised phishing material, build supporting infrastructure and summarise exfiltrated data.

Full autonomy has not yet been observed

GTIG said it has not yet observed threat actors operating completely autonomous pipelines capable of discovering zero-day vulnerabilities and independently executing intrusions in real-world campaigns.

However, groups are already constructing more sophisticated, multi-stage attack workflows with reduced human involvement. AI is allowing them to turn published vulnerabilities into functional exploits more quickly and operate campaigns at greater speed and scale.

The trend creates a growing challenge for European governments, armed forces and defence manufacturers, particularly smaller suppliers that may hold sensitive technical information but lack the cybersecurity resources of major contractors.

Google said it had disabled infrastructure and accounts associated with detected misuse and strengthened safeguards designed to prevent its models from supporting malicious operations.

Source: Google Threat Intelligence Group