Criminal hackers used AI to write working zero-day exploit

Source Cryptopolitan

Google’s Threat Intelligence Group said Sunday it caught what it believes is the first zero-day exploit built with help from an AI model.

A criminal hacking group wrote it as a Python script to bypass two-factor authentication (2FA) in an open-source web admin tool, according to a report Google published on its Cloud Blog. The company worked with the vendor to stop mass exploitation before it started.

Google linked the exploit to AI through code patterns

Google didn’t blame its own Gemini model. Analysts pointed to structural patterns in the code that strongly suggest AI involvement.

“Based on the structure and content of these exploits, we have high confidence that the actor likely leveraged an AI model to support the discovery and weaponization of this vulnerability,” Google wrote.

The Python script had unusually detailed educational docstrings, a hallucinated CVSS severity score, and formatting typical of large language model output.

That includes structured help menus and a clean color class written in textbook style.

Google hasn’t named the hacking group or the specific tool that was targeted.

State backed hackers use AI models for vulnerability research

Google’s report goes beyond the single zero-day case.

China and North Korea linked hackers have shown a strong interest in using AI to find and take advantage of software flaws, according to Google’s Threat Intelligence Group.

A Chinese threat group known as UNC2814 attacks telecom and government targets. The group used a technique Google calls persona-driven jailbreaking.

The group instructed an AI model to behave as a senior security auditor, then directed it to analyze embedded device firmware from TP-Link and Odette File Transfer Protocol implementations for remote code execution vulnerabilities.

The group prompted an AI model to act as a senior security auditor, then directed it to search TP-Link embedded device firmware and Odette File Transfer Protocol implementations for remote code execution vulnerabilities.

A different group with ties to China used tools called Strix and Hexstrike to attack a Japanese tech firm and a major East Asian cybersecurity company.

Google catches first zero-day exploit built with AI assistance.
Hackers leverage AI to find and exploit zero-day vulnerabilities fast. Source: Google Cloud Blog.

North Korean group APT45 took a different approach. It sent thousands of repetitive prompts to recursively analyze known CVE entries and validate proof-of-concept exploits.

Google said this method produced “a more robust arsenal of exploit capabilities that would be impractical to manage without AI assistance.”

AI enables new forms of malware and evasion

The Google report covers other AI threats beyond vulnerability research.

Suspected Russian hackers have used AI to code and build polymorphic malware and obfuscation networks. That malware accelerates development cycles and helps them evade detection.

Google also warned about a type of malware it calls PROMPTSPY, which it described as a change toward autonomous attack operations. The malware uses AI models to interpret system states and dynamically generate commands to manipulate victim environments. Attackers can hand off operational decisions to the model itself.

Threat actors now procure anonymized premium-tier access to language models via specialized middleware and automated account registration systems. These services enable hackers to circumvent usage restrictions en masse by utilizing trial accounts to finance their activities.

A group Google tracks as TeamPCP, also known as UNC6780, has begun targeting AI software dependencies as an entry point into broader networks. They use compromised AI tools as a foothold for ransomware deployment and extortion.

Google said it uses its own AI tools defensively. The company referenced Big Sleep, an AI agent that identifies software vulnerabilities, and CodeMender, which uses Gemini’s reasoning to automatically patch flaws.

Google also said it disables accounts caught misusing Gemini for malicious purposes.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Natural Gas sinks to pivotal level as China’s demand slumpsNatural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
Author  FXStreet
Jul 01, 2024
Natural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
placeholder
ECB Policy Outlook for 2026: What It Could Mean for the Euro’s Next MoveWith the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
Author  Mitrade
Dec 26, 2025
With the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
placeholder
My Top 5 Stock Market Predictions for 2026Five 2026 market predictions written in a native, news-style voice: AI’s winners and losers, broader sector leadership, dividend demand, valuation cooling as the Shiller CAPE sits at 39 (Dec. 31, 2025), and quantum-computing bursts—while keeping all original facts and numbers unchanged.
Author  Mitrade
Jan 06, Tue
Five 2026 market predictions written in a native, news-style voice: AI’s winners and losers, broader sector leadership, dividend demand, valuation cooling as the Shiller CAPE sits at 39 (Dec. 31, 2025), and quantum-computing bursts—while keeping all original facts and numbers unchanged.
placeholder
Silver Price Analysis: Climbs above $80, as bulls eye weekly highSilver price advances more than 2.50% on Friday, set to end the week with gains of over 7% sponsored by US Dollar weakness and falling oil prices. At the time of writing, the XAG/USD trades at $80.72, after bouncing off daily lows of $78.16.
Author  FXStreet
May 09, Sat
Silver price advances more than 2.50% on Friday, set to end the week with gains of over 7% sponsored by US Dollar weakness and falling oil prices. At the time of writing, the XAG/USD trades at $80.72, after bouncing off daily lows of $78.16.
placeholder
Gold slumps below $4,700 on Trump rejection of Iran peace proposalGold price (XAU/USD) falls to around $4,690 during the early Asian session on Monday. The precious metal attracts some sellers after US President Donald Trump rejected Iran’s latest peace offer to end the 10-week conflict choking the Strait of Hormuz, fanning inflation fears. 
Author  FXStreet
22 hours ago
Gold price (XAU/USD) falls to around $4,690 during the early Asian session on Monday. The precious metal attracts some sellers after US President Donald Trump rejected Iran’s latest peace offer to end the 10-week conflict choking the Strait of Hormuz, fanning inflation fears. 
goTop
quote