Google Threat Intelligence Group reported that threat actors are moving beyond experimentation with artificial intelligence and are increasingly integrating AI into real-world malicious operations. The update highlights adversarial interest in model distillation, which can reproduce capabilities of larger systems in smaller, cheaper models, alongside continued testing of AI for tasks such as content generation, workflow acceleration, and operational support.
The report indicates that AI adoption by attackers remains evolutionary rather than revolutionary, with actors using the technology to improve efficiency instead of fundamentally changing tradecraft. Google’s tracking suggests the most notable developments are the refinement of distilled models, broader experimentation across criminal and state-linked ecosystems, and the continued embedding of AI into existing intrusion, influence, and cyber-enabled activity.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Google Cloud published a Mandiant Threat Intelligence blog post titled "GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use." No underlying incident details are provided in the reference content, so the publication itself is the only discrete event that can be extracted.
Google Cloud published a Mandiant Threat Intelligence blog post titled "Adversarial Misuse of Generative AI." Based on the provided content, the publication itself is the discrete event that can be extracted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.