# Google Threat Intelligence Group (GTIG): Advances in Threat Actor Usage of AI Tools

Source: https://www.youtube.com/watch?v=zgciWxxIk2Y
Recap page: https://rapidrecap.app/video/zgciWxxIk2Y
Generated: 2025-11-12T00:09:53.166+00:00

---
## Quick Overview

Google Threat Intelligence Group (GTIG) reports that threat actors are increasingly using Large Language Models (LLMs) like Google's Gemini for sophisticated, real-time, and polymorphic attacks, exemplified by actors like APT28 (Frozen Lake) employing LLMs to generate evasive malware and tailor social engineering attacks against specific targets, fundamentally shifting the threat landscape from static attacks to dynamic, AI-enabled operations.

**Key Points:**
- Threat actors, including APT28 (Frozen Lake), now use LLMs like Gemini to generate polymorphic malware and tailor social engineering attacks in real-time.
- The report details a G-TIG incident where an actor used Gemini to generate an obfuscated VBScript dropper and a Python-based command-and-control server.
- The APT42 actor, also known as Muddy Coast, used Gemini 1.5 to query for new evasion code and generate convincing social engineering lures in Spanish.
- The use of LLMs allows threat actors to bypass traditional security measures like antivirus signatures and greatly lowers the technical skill barrier for complex attacks.
- The attackers successfully used an LLM to create a malicious script that dynamically changed its behavior based on specific system information, demonstrating a significant operational leap.
- Google and other providers are actively monitoring this trend, leading to countermeasures like disabling accounts and patching vulnerabilities in their own systems, such as the Gemini API.
- This development forces defenders to focus on countering dynamic, AI-driven threats rather than relying solely on static defenses.

![Screenshot at 03:40: The discussion transitions to the specific case of APT28 \(Frozen Lake\) using an LLM to generate malware, highlighting the shift from static to dynamic attack methods.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-03-40.png)

**Context:** This video discusses findings from the Google Threat Intelligence Group (GTIG) regarding the evolving tactics of threat actors who are leveraging advanced Large Language Models (LLMs) for malicious cyber operations. The context centers on a specific report detailing how state-sponsored groups are moving beyond simple, static malware to create highly adaptive, real-time attack tools, forcing a paradigm shift in defensive strategies.

## Detailed Analysis

The GTIG report confirms that threat actors are entering a major paradigm shift in cyber warfare by deploying AI tools like LLMs, moving away from static, predictable attacks. Threat actors are using these tools to automate reconnaissance, rapidly develop custom malware, and tailor phishing and social engineering campaigns in real-time. The report specifically cites examples from state-sponsored actors: APT28 (Frozen Lake) used Gemini to generate an obfuscated VBScript dropper and a Python C2 server, and APT42 (Muddy Coast) used Gemini 1.5 to query for novel evasion techniques and generate persuasive Spanish-language lures targeting specific system information. The LLMs are effectively becoming active participants in the attack chain, dynamically altering their behavior and even generating code to bypass security measures like antivirus signatures, as seen when one actor prompted the model to generate code that recursively copied files to evade detection. This high level of customization and real-time adaptation represents a major leap in offensive capabilities, forcing defenders to address dynamically evolving threats rather than relying on static defenses. The discussion concludes by noting that major providers like Google are continuously working to mitigate these risks by patching their own systems and disabling accounts linked to such misuse.

### GTIG Report Findings

- AI signals a major paradigm shift in cyber warfare
- LLMs enable dynamic, real-time attack creation
- Threat actors are becoming rapidly reliant on these tools.

### APT28 (Frozen Lake) Tactics

- Used Gemini to generate obfuscated VBScript dropper and Python-based C2 server
- Successfully created malware that dynamically altered behavior based on system info.

### APT42 (Muddy Coast) Tactics

- Used Gemini 1.5 to query for new evasion codes and generate Spanish-language social engineering lures.
- Targeted specific infrastructure like AWS tokens for EC2 instances.

### Impact on Defense

- LLM-enabled attacks bypass traditional security signatures
- Technical skill barrier for complex attacks is lowered
- Defense must shift from static detection to countering dynamic threats.

### Mitigation and Future

- Google and providers are disabling accounts and patching systems like the Gemini API
- The complexity of countering these attacks is rising, creating tension between offense and defense.

![Screenshot at 00:01: Introduction screen displaying the podcast title and a call to action to become a member.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-00-01.png)
![Screenshot at 00:15: Visual representation of the AI threat tracker concept, framing the discussion context.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-00-15.png)
![Screenshot at 01:18: Speaker mentions the static nature of pre-AI malware instructions compared to current methods.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-01-18.png)
![Screenshot at 02:54: Speaker emphasizes that the malware code generated by the LLM evolves over time.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-02-54.png)
![Screenshot at 03:38: Specific mention of state-sponsored actors like APT28 \(Frozen Lake\) being observed using these tactics.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-03-38.png)
![Screenshot at 05:04: Discussion shifts to the defensive implications, noting that major providers are investing heavily in prevention.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-05-04.png)
![Screenshot at 07:08: Visual of the waveform overlaid on the screen, emphasizing the ongoing nature of the threat landscape.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-07-08.png)
![Screenshot at 09:25: The speaker notes the use of LLMs to target less conventional attack surfaces like cloud environments.](https://ss.rapidrecap.app/screens/zgciWxxIk2Y/00-09-25.png)
