Google: Iran expanding AI use in cyberattacks and influence operations

Tech giant says Iranian and Chinese hackers are using AI to build attack infrastructure, create fake online personas and evade security tools, while autonomous agents can now carry out complex operations with limited human oversight

Google says Iranian state-backed hackers are rapidly expanding their use of artificial intelligence, moving beyond simple prompts and phishing assistance to developing attack infrastructure, creating sophisticated fake online identities and attempting to bypass corporate security systems.
New findings released Tuesday by Google’s threat intelligence team point to what the company describes as a broader shift in cyberwarfare: from humans using AI as an assistant to autonomous AI agents capable of carrying out complex operations with limited ongoing supervision.
האקר איראני
האקר איראני
Iran expands AI use in cyber operations as autonomous agents speed up attacks, Google says
(Photo: Shutterstock)
At the center of the report is growing activity linked to Iran, alongside Chinese espionage groups and financially motivated cybercriminals. Google says the trend is dramatically shortening the window defenders have to detect and stop attacks.
An Iranian government-linked hacking group known as CALANQUE ION, also tracked as APT42 and believed to be affiliated with Iran’s Islamic Revolutionary Guard Corps, has expanded its use of large language models, including Google’s Gemini.
The group has previously used AI for familiar tasks such as gathering open-source intelligence and drafting targeted phishing messages. Google says it is now going further, using models to help develop tactical attack infrastructure and experiment with reverse-engineering software licensing systems in an effort to circumvent advanced corporate defenses.
Iranian influence operations are also becoming more sophisticated.
According to Google, Iranian actors are no longer relying only on basic instructions when generating synthetic content. They are prompting language models to produce highly detailed instructions for image-generation systems, specifying elements such as studio lighting, camera angles and skin texture to create photorealistic online personas.
The operators also instruct models to adopt specialist identities, such as energy-market analysts or psychological-warfare experts, and to incorporate advanced persuasion techniques into narratives designed to advance Tehran’s objectives.
The findings come as autonomous AI agents take on a growing role in offensive cyber operations.
In one case documented by Google, a financially motivated attacker gained access to corporate cloud resources and, in less than six hours, planned, built and executed a large-scale campaign to steal credentials and scan for vulnerabilities.
The AI agent managed the scanning operation itself, troubleshot problems in real time and automatically rotated network addresses in an effort to avoid detection.
Google’s report also describes an emerging contest between attackers and AI-powered defensive tools.
A financially motivated cybercrime group tracked as UNC6780, also known as TeamPCP, developed a method designed to interfere with security scanners that rely on language models.
The attackers embedded comments inside source code containing extreme instructions related to the production of biological or nuclear weapons. When an automated scanner encountered the prohibited material, its internal safety mechanisms could refuse to process the file, allowing malicious code to escape inspection and continue operating in the development environment.
Chinese state-linked activity presents another challenge.
Google says espionage group UNC6508 has continued targeting intellectual property and AI research at academic, medical and defense institutions in North America.
After compromising cloud environments, the group has deployed open-source models inside them, allowing attackers to exploit the victim’s costly computing resources while avoiding some of the monitoring and security controls built into commercial AI application programming interfaces.
The report also highlights how threat actors are spreading their activity across a wide range of AI tools.
Alongside closed models such as Anthropic’s Claude and Google’s Gemini, attackers have used specialized coding assistants including China’s DeepSeek-Coder to develop malicious software. They have also targeted configuration files and access credentials associated with modern development environments and AI coding tools such as Cursor, Devin and Cline.
Google said the malicious activity it identified triggered its security protections and that the accounts and projects involved were blocked.
The company added that its DeepMind division is using the findings to strengthen safety filters and reduce the likelihood that its models can be used to support future cyberattacks.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""