# Google warns Iran expands AI use in cyberattacks and influence operations

> Source: <https://cryptobriefing.com/google-iran-ai-cyberattacks-influence-operations/>
> Published: 2026-09-08 16:53:18+00:00

Photo: Bastian Riccardi / Pexels

# Google warns Iran expands AI use in cyberattacks and influence operations

Iranian state-backed groups are the most prolific nation-state exploiters of Google's Gemini AI, with over ten distinct threat groups identified using the model for everything from phishing to fabricating fake identities.

Iran’s cyber operators have found a new favorite tool, and it belongs to [Google](https://cryptobriefing.com/markets/alphabet/). The company’s Threat Intelligence Group (GTIG) has identified more than ten Iranian state-backed groups actively exploiting its Gemini AI model to supercharge cyberattacks, build fake online personas, and run disinformation campaigns at scale.

Iranian actors now represent the single largest nation-state user demographic of Gemini among threat groups GTIG tracks. Iranian information operations account for roughly 75% of all AI-assisted disinformation efforts the group has observed.

## What Iran is actually doing with Gemini

The most active offender is APT42, also known as GreenBravo, a group widely linked to Iran’s Islamic Revolutionary Guard Corps. APT42 alone is responsible for over 30% of all Iranian APT activity involving Gemini, according to Google’s analysis.

Their playbook includes reconnaissance on potential targets, crafting convincing phishing campaigns, writing and debugging code for attack tools, and studying specific techniques to improve their operations.

GTIG’s Q3 AI Threat Tracker reported that Iranian actors are now using Gemini to design photorealistic fake identities, complete with counter-narratives aligned to the Iranian state’s strategic objectives.

APT42 was observed deploying Gemini for reconnaissance and technique research in the period just before escalations in conflict in late February 2026, illustrating how these tools are being woven into the timing and tempo of real-world geopolitical events.

## Efficiency boost, not a revolution

Iran isn’t using AI to invent entirely new categories of cyberattacks. Instead, generative AI is functioning as a productivity multiplier for tactics that have existed for years. The broader ecosystem of threat reporting corroborates this pattern: AI tools have reinforced Iran-linked cyber operations without producing fundamentally novel attack methodologies.

## A pattern Google has been tracking since early 2025

Google’s monitoring of Gemini exploitation by state actors isn’t new. The company first outlined the problem in a January 2025 report, which initially flagged APT42 and its peers as significant abusers of the platform.

Iran’s cyber capabilities are deeply rooted in state infrastructure, particularly the IRGC. While China, Russia, and North Korea all maintain significant cyber programs, Iranian groups have emerged as the most prolific exploiters of commercially available AI models, accounting for 75% of AI-powered influence operations GTIG detected.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
