North Korea-Linked UNC2970 Uses Gemini For Reconnaissance

Google said on Thursday, Feb. 12, 2026, it observed the North Korea-linked threat actor UNC2970 using its generative AI model Gemini to conduct reconnaissance on targets. The company warned hackers and other groups are weaponizing Gemini to accelerate attack lifecycle phases, enable information operations, and perform model-extraction attacks. The activity underscores growing misuse of LLMs in cyber operations.
Scoring Rationale
Official Google disclosure elevates urgency for defenders and industry, but concise reporting limits specific mitigation steps and technical detail.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problemsStep-by-step roadmaps from zero to job-ready — curated courses, salary data, and the exact learning order that gets you hired.
Sources
- Read OriginalGoogle Reports State-Backed Hackers Using Gemini AI for Recon and Attack Supportitsecuritynews.info

