Google’s Threat Intelligence Group (GTIG) has identified more than ten Iranian state-backed groups actively exploiting the company’s Gemini AI model. Iranian actors now represent the largest nation-state user demographic of Gemini among tracked threat groups, accounting for approximately 75% of all AI-assisted disinformation operations detected. APT42, linked to Iran’s Islamic Revolutionary Guard Corps, is the most active offender, responsible for over 30% of all Iranian APT activity involving Gemini. These groups use AI for target reconnaissance, phishing campaign crafting, malicious code writing, and creating photorealistic fake identities aligned with Iranian strategic objectives. Google first flagged this issue in a January 2025 report.
Source: Read the original article

