Google Threat Intelligence Reveals North Korean and Chinese State Actors Using AI for Exploit Development
GTIG's May 12 report identifies a criminal threat actor using an AI-generated zero-day exploit against a hardcoded 2FA bypass flaw in a popular open-source web administration tool, which the group said is the first such case it has documented. The actor had planned a mass exploitation event, and GTIG said its proactive counter-discovery may have prevented the operation. GTIG attributed the exploit to AI assistance with high confidence based on educational docstrings, a hallucinated CVSS score, and structured Pythonic formatting in the code, and stated that Gemini was not used. Separately, GTIG documented PRC-nexus
The documented AI-generated zero-day belongs to a cybercrime actor, not a state-sponsored one, and the forecast turns on that distinction. PRC- and DPRK-nexus clusters have scaled to AI-assisted CVE analysis and proof-of-concept validation at volume, per a single GTIG technical report without independent corroboration, but neither has produced a publicly attributed AI-developed exploit. A state-actor AI-generated zero-day is
4 sources
- Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access -
Google Cloud Blog - Google Detects First AI-Generated Zero-Day Exploit -
SecurityWeek - Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation -
The Hacker News - Google says it likely thwarted effort by hacker group to use AI for 'mass exploitation event' -
CNBC