Skip to main content
TopAIThreats home TOP AI THREATS
INC-26-0101 confirmed high Signal

State-Sponsored Adversary Use of the Gemini API for Vulnerability Research and Operational Support (2026)

Attribution

Google develops and operates the Gemini API. UNC2814, APT45, and APT27 used that API for vulnerability research and offensive tooling development, and Google disabled the assets associated with the activity. Google is named here as the model provider, not as a party to the adversary operations.

Threat actor(s): UNC2814, APT45, APT27

Incident Details

Last Updated 2026-08-11

On May 11, 2026 the Google Threat Intelligence Group reported that multiple state-sponsored threat actors had used the Gemini API for vulnerability research and offensive support. GTIG observed PRC-nexus UNC2814 using expert-persona prompting, directing the model to act as a senior security auditor or C/C++ binary security expert, to seek security analysis of TP-Link firmware and Odette File Transfer Protocol implementations. DPRK-aligned APT45 was observed sending thousands of repetitive prompts that recursively analyzed CVEs and validated proof-of-concept exploits. PRC-nexus APT27 leveraged Gemini to accelerate development of a fleet-management application supporting an operational relay box (ORB) network. A separate, unattributed criminal case involving AI-assisted zero-day development is recorded as INC-26-0105.

Incident Summary

On May 11, 2026, the Google Threat Intelligence Group (GTIG) published a report on AI-enabled vulnerability exploitation and initial access, describing observed use of the Gemini API by multiple state-sponsored threat actors for vulnerability research and offensive support.[1]

GTIG named three state-aligned clusters. It reported observing UNC2814, a PRC-nexus group, “use this form of expert persona prompting by directing the model to act as a senior security auditor or C/C++ binary security expert,” seeking vulnerability analysis of TP-Link firmware and Odette File Transfer Protocol implementations. APT45, a DPRK-aligned group, was observed “sending thousands of repetitive prompts that recursively analyze different CVEs and validate PoC exploits.” APT27, also PRC-nexus, “leveraged Gemini to accelerate the development of a fleet management application” supporting an operational relay box (ORB) network.[1]

GTIG places expert-persona prompting in the context of “persona-driven jailbreaking attempts” and prompt injection. It does not publish refusal rates or control-testing results, so the extent to which Gemini’s safety controls were bypassed rather than simply not triggered is not established in the public record.

Google reported taking action against the documented activity by disabling the associated assets.[1] The disclosure was covered by BleepingComputer, CSO Online, SiliconANGLE, and other outlets.[2][3][4]

A separate case in the same GTIG report, involving an unattributed criminal actor and AI-assisted development of a working zero-day exploit, is recorded separately as INC-26-0105. The two are kept apart because their actors, attribution confidence, and outcomes differ.

Key Facts

  • Disclosure source: Google Threat Intelligence Group, published May 11, 2026
  • State-aligned actors named: UNC2814 (PRC-nexus), APT45 (DPRK-aligned), APT27 (PRC-nexus)
  • Model involved: Google Gemini, accessed via the Gemini API. Google is the model provider; the threat actors were users of that API, not its developers or deployers
  • Techniques described: Expert-persona prompting, recursive CVE analysis across thousands of repetitive prompts, AI-assisted development of offensive support tooling
  • Targets cited: TP-Link firmware, Odette File Transfer Protocol, ORB-network fleet management
  • Vendor response: Google reported disabling the assets associated with the documented activity
  • Observation dates: Not published by GTIG, which describes the activity only as recently observed
  • Related record: INC-26-0105 covers the unattributed criminal AI-assisted zero-day case from the same report

Threat Patterns Involved

Primary: Automated Vulnerability Discovery — APT45’s recursive CVE-analysis workflow and UNC2814’s expert-persona security-audit prompts both use an LLM to assist vulnerability triage and exploit validation.

Secondary:

  • Jailbreak & Guardrail Bypass — GTIG characterizes expert-persona prompting within its discussion of persona-driven jailbreaking attempts. The public record describes the technique, not a measured bypass rate.
  • Tool Misuse & Privilege Escalation — APT27’s use of Gemini for ORB fleet-management development illustrates a general-purpose assistant being applied to offensive-operations tooling.

Significance

GTIG’s report documents adversary use of a commercial LLM in security-relevant workflows, at a scale and specificity not previously published for these actors.

  1. State adoption is described as repetitive and high-volume. GTIG’s account of APT45 sending “thousands of repetitive prompts that recursively analyze different CVEs and validate PoC exploits” describes a triage workflow rather than isolated experimentation.
  2. Expert-persona framings remain a live concern for frontier safeguards. GTIG situates UNC2814’s prompting within persona-driven jailbreaking. Whether current alignment training reliably refuses adversarial security-research framings is not answered by this disclosure.
  3. The provider holds an observation position defenders do not. Prompt-level activity is visible to the model vendor rather than to endpoint or network defenders, which is why the documented response came from Google disabling assets.

Analyst assessment

The following are this project’s interpretations rather than findings stated by GTIG, and they are not established by the incident record alone.

  • LLM assistance may reduce the marginal effort of CVE triage for actors with API access, though the disclosure does not quantify any productivity change.
  • Detection of this class of activity appears to concentrate at the model-provider layer. Endpoint and network defenders may have limited visibility into prompt-level workflows, which suggests provider-side monitoring carries disproportionate weight for this threat class.
  • Asset disablement addresses observed accounts. It does not, on its own, indicate whether actors migrated to alternative commercial or open-weights models.

Timeline

Google Threat Intelligence Group publishes its report on AI-enabled vulnerability exploitation and initial access, describing observed Gemini API use by UNC2814, APT45, and APT27. GTIG describes the activity as 'recently observed' and does not publish dated observation windows for the individual actors.

Google reports taking action against the documented activity by disabling the associated assets

Use in Retrieval

INC-26-0101 documents State-Sponsored Adversary Use of the Gemini API for Vulnerability Research and Operational Support, a high-severity incident classified under the Security & Cyber domain and the Automated Vulnerability Discovery threat pattern (PAT-SEC-003). It occurred in Global, Asia, East Asia (2026-01). This page is maintained by TopAIThreats.com as part of an evidence-based registry of AI-enabled threats. Cite as: TopAIThreats.com, "State-Sponsored Adversary Use of the Gemini API for Vulnerability Research and Operational Support," INC-26-0101, last updated 2026-08-11.

Sources

  1. Google Threat Intelligence Group: AI-Enabled Vulnerability Exploitation and Initial Access (primary, 2026-05)
    https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access (opens in new tab)
  2. BleepingComputer: Google — Hackers Used AI to Develop Zero-Day Exploit for Web Admin Tool (news, 2026-05)
    https://www.bleepingcomputer.com/news/security/google-hackers-used-ai-to-develop-zero-day-exploit-for-web-admin-tool/ (opens in new tab)
  3. CSO Online: Google Discovers Weaponized Zero-Day Exploits Created with AI (news, 2026-05)
    https://www.csoonline.com/article/4169046/google-discovers-weaponized-zero-day-exploits-created-with-ai.html (opens in new tab)
  4. SiliconANGLE: Google Says Criminals Used AI to Build a Working Zero-Day Exploit for the First Time (news, 2026-05)
    https://siliconangle.com/2026/05/11/google-says-criminals-used-ai-build-working-zero-day-exploit-first-time/ (opens in new tab)
  5. Cybersecurity News: Google Warns of Hackers Using AI to Create Working Zero-Day Exploit (news, 2026-05)
    https://cybersecuritynews.com/ai-zero-day-exploit/ (opens in new tab)
  6. Crypto Times: Google Exposes How Hackers Are Using AI to Target Crypto and Beyond (news, 2026-05)
    https://www.cryptotimes.io/2026/05/13/google-exposes-how-hackers-are-using-ai-to-target-crypto-and-beyond/ (opens in new tab)

Update Log

  • — First logged (Status: Confirmed, Evidence: Primary)