DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use

Forensic Summary

Google Threat Intelligence Group's Q4 2025 AI Threat Tracker documents a meaningful escalation in adversarial AI misuse, including a surge in model extraction (distillation) attacks, nation-state operationalisation of LLMs for phishing and reconnaissance, and the emergence of AI-integrated malware families such as HONESTCUE that leverage Gemini's API. While no breakthrough capabilities have been observed from APT actors, the integration of agentic AI for tooling development signals a maturing threat landscape. Defenders should prioritise monitoring for model extraction activity, API abuse, and AI-augmented social engineering campaigns.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/gtig-ai-threat-tracker-distillation-experimentation-and-continued-integration-of/

Top comments (0)