AI-Powered Threat Actors Dominate Cybersecurity Landscape
Google's Threat Intelligence Group (GTIG) has released its AI Threat Tracker report for Q3 of 2026, revealing the growing use of artificial intelligence by threat actors. According to John Hultquist, Chief Analyst at Google GTIG, all threat actors are now using AI in some capacity, and their operations have benefited from it.
The report highlights several examples of how threat actors are leveraging AI to aid cyberattacks. For instance, the Russian group UNC5792 is using AI to turn large volumes of information into actionable intelligence by analyzing Telegram channels for information of interest to Russian authorities.
Another prominent Russian cyber espionage group, SANDWORM RELIC (also tracked as FROZENBARENTS, SANDWORM and APT44), has integrated Gemini into its operations targeting Ukraine. The group is using AI to gather intelligence, conduct social engineering, and automate workflows.
The report also notes that threat actors are relying on AI to aid their influence operations, with Iranian actors using Gemini to construct 'highly detailed prompts for text-to-image generators' to create photorealistic fictitious personas as part of their campaign.