Adversary Intelligence — 2026-05-12

Google Threat Intelligence Reveals North Korean and Chinese State Actors Using AI for Exploit Development

GTIG's May 12 report identifies a criminal threat actor using an AI-generated zero-day exploit against a hardcoded 2FA bypass flaw in a popular open-source web administration tool, which the group said is the first such case it has documented. The actor had planned a mass exploitation event, and GTIG said its proactive counter-discovery may have prevented the operation. GTIG attributed the exploit to AI assistance with high confidence based on educational docstrings, a hallucinated CVSS score, and structured Pythonic formatting in the code, and stated that Gemini was not used. Separately, GTIG documented PRC-nexus APT45 sending thousands of automated prompts to analyze CVEs and validate proof-of-concept exploits at scale, and UNC2814 using expert persona prompting on Gemini for embedded device vulnerability research.

Analysis
The documented AI-generated zero-day belongs to a cybercrime actor, not a state-sponsored one, and the forecast turns on that distinction. PRC- and DPRK-nexus clusters have scaled to AI-assisted CVE analysis and proof-of-concept validation at volume, per a single GTIG technical report without independent corroboration, but neither has produced a publicly attributed AI-developed exploit. A state-actor AI-generated zero-day is unlikely by end of November 2026, with moderate confidence; the barrier is tradecraft, not capability, as state actors sanitize forensic AI artifacts and rarely trigger the proactive counter-discovery that exposed this case. The forensic markers underpinning the criminal attribution, including educational docstrings, a hallucinated CVSS score, and Pythonic formatting, could equally reflect deliberate mimicry, which would nullify the "first confirmed" designation.
4 sources
  1. Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - Google Cloud Blog
  2. Google Detects First AI-Generated Zero-Day Exploit - SecurityWeek
  3. Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation - The Hacker News
  4. Google says it likely thwarted effort by hacker group to use AI for 'mass exploitation event' - CNBC

View in full brief →

UNCLASSIFIED // OPEN SOURCE