Google’s Threat Intelligence Group says it has uncovered what may be the first documented case of cybercriminals using artificial intelligence to help develop a zero-day exploit.
According to a blog post released Tuesday, Google identified a coordinated cybercrime operation in which threat actors allegedly used an AI model to discover and weaponize a vulnerability in a widely used open-source, web-based system administration platform. The flaw reportedly enabled attackers to bypass two-factor authentication (2FA), provided they already possessed valid login credentials.
The vulnerability allowed hackers to skip the second security verification step — a critical protection layer commonly used to secure financial platforms, crypto wallets, and online accounts.
Google stated it has “high confidence” the attackers relied on AI during both the discovery and exploitation phases. Investigators pointed to unusual characteristics within the exploit code, including formatting patterns and even hallucinated content typically associated with large language models (LLMs).
Unlike many traditional vulnerabilities caused by coding mistakes such as memory corruption, Google said this flaw involved a deeper “semantic logic” issue, where developers had unintentionally hardcoded a faulty trust assumption into the system.
The company explained that advanced LLMs are particularly effective at spotting these kinds of high-level logic weaknesses and identifying abnormal hardcoded behaviors that human reviewers may overlook.
Google did not publicly identify the group behind the operation, but noted that both China and North Korea have shown growing interest in using AI to accelerate vulnerability research and offensive cyber operations.
The report also highlighted how AI is increasingly being integrated into malware development. Malware families including PROMPTFLUX, HONESTCUE, and CANFAIL are reportedly using LLMs to generate decoy code and disguise malicious behavior, making detection more difficult for security systems.
Google warned that abuse of AI platforms is becoming increasingly industrialized. Threat actors are now creating automated systems to rotate premium AI accounts, share API keys, and bypass platform safety protections at scale. By combining anti-detect browsers with account-pooling techniques, attackers can maintain large-scale anonymous access to advanced AI models for cyber operations.
The company concluded that as more organizations integrate LLMs into production environments, the broader AI ecosystem itself is becoming a growing target for exploitation. Attackers are increasingly focusing on connected tools such as autonomous AI agents and third-party data integrations, though Google said there is still no evidence that threat actors have successfully bypassed the core security protections of leading frontier AI models.

