Google: China's APT31 used Gemini to plan cyberattacks against US orgs 12.02.2026

Google has reported that the Chinese government-backed hacking group APT31, also known as Violet Typhoon, utilized Google's AI chatbot, Gemini, to automate the analysis of vulnerabilities and plan cyberattacks against US organizations. While no successful attacks have been confirmed, this development signifies a growing trend of advanced persistent threat (APT) groups leveraging AI for semi-autonomous offensive operations. APT31 employed a structured approach, prompting Gemini with a cybersecurity persona and integrating it with the open-source red-teaming tool Hexstrike to identify and test exploits against US targets. Google has since disabled accounts linked to this activity and is actively working to counter the misuse of its AI tools, emphasizing the need for AI-driven defenses to respond at machine speed.



















