{"id":873,"date":"2026-05-11T17:30:43","date_gmt":"2026-05-11T17:30:43","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=873"},"modified":"2026-05-11T17:30:43","modified_gmt":"2026-05-11T17:30:43","slug":"hackers-used-ai-to-develop-first-known-zero-day-2fa-bypass-for-mass-exploitation","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=873","title":{"rendered":"Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgF329-zAoI4gwIW3h3gRYiDJjcRSyWPM4DLHFQwNNGfLTVaROqIfQZ0QB1FwWGmvMGuyNAF9Q6QBYcwLsqMsCka5Lqu82CzUbrBULnUDQwtY_4z6KiOEKSETes6as77XfUCaJVBUOCovZz8jajp6vBp9AAjHiS7BEviANEH0FxmzZwdrTapD3R-gPQWKJ1\/s1700-e365\/ai-hacker.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation.<\/p>\n<p>The activity is said to be the work of cybercrime threat actors who appear to have collaborated together to plan what the tech giant described as a \u00abmass vulnerability exploitation operation.\u00bb<\/p>\n<p>\u00abOur analysis of exploits associated with this campaign identified a zero-day vulnerability implemented in a Python script that enables the user to bypass two-factor authentication (2FA) on a popular open-source, web-based system administration tool,\u00bb Google Threat Intelligence Group (GTIG) <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/ai-vulnerability-exploitation-initial-access\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>The tech giant said it worked with the impacted vendor to responsibly disclose the flaw and get it fixed in order to proactively disrupt the activity. It did not disclose the name of the tool.<\/p>\n<p>Although there is no evidence to suggest that Google&#8217;s Gemini AI tool was used to aid the threat actors, GTIG assessed with high confidence that an AI model was weaponized to facilitate the discovery and weaponization of the flaw via a Python script that featured all hallmarks typically associated with large language model (LLM)-generated code.<\/p>\n<p>\u00abFor example, the script contains an abundance of educational docstrings, including a hallucinated CVSS score, and uses a structured, textbook Pythonic format highly characteristic of LLMs training data (e.g., detailed help menus and the clean _C ANSI color class),\u00bb GTIG added.<\/p>\n<p>The vulnerability, described as a 2FA bypass, requires valid user credentials for exploitation. It stems from a high-level semantic logic flaw arising as a result of a hard-coded trust assumption, something LLMs excel at spotting.<\/p>\n<p>\u00abAI is already accelerating vulnerability discovery, reducing the effort needed to identify, validate, and weaponize flaws,\u00bb Ryan Dewhurst, watchTowr&#8217;s Head of Threat Intelligence, told The Hacker News in a statement. \u00abThis is today&#8217;s reality: discovery, weaponization, and exploitation are faster. We&#8217;re not heading toward compressed timelines; we&#8217;ve been watching the timelines compress for years. There is no mercy from attackers, and defenders don&#8217;t get to opt out.\u00bb\u00a0<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The development comes as AI is not only acting as a force multiplier for vulnerability disclosure and abuse, but is also enabling attackers to develop polymorphic malware and conduct autonomous malware operations, as observed in the case of PromptSpy, an Android malware that abuses Gemini to analyze the current screen and provide it with instructions to pin the malicious app in the recent apps list.<\/p>\n<p>Further investigation of the backdoor has uncovered a broader set of capabilities to allow the malware to navigate the Android user interface and autonomously monitor and interpret real-time user activity to determine the next course of action using an autonomous agent module.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgIkAkJGxHAQrF6vYJB3iCxnn4QQN9Uv3OpLVib_rVEKc50g0alInqFB0uuEBx6mD0f7FzYOBkvBu5sp7k0fIaxtvLKDsiwHYJtjobhJ88BjHYDlFKN3fFfcBBI_mbmvkxV0uTvLQ76kGmLHSzb9uXw-1lJwF1uCqB3Dw-V2TTD_N7S0ZAiUolgGXDXtmQp\/s1700-e365\/actor.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgIkAkJGxHAQrF6vYJB3iCxnn4QQN9Uv3OpLVib_rVEKc50g0alInqFB0uuEBx6mD0f7FzYOBkvBu5sp7k0fIaxtvLKDsiwHYJtjobhJ88BjHYDlFKN3fFfcBBI_mbmvkxV0uTvLQ76kGmLHSzb9uXw-1lJwF1uCqB3Dw-V2TTD_N7S0ZAiUolgGXDXtmQp\/s1700-e365\/actor.png\" alt=\"\" border=\"0\" data-original-height=\"257\" data-original-width=\"1000\"\/><\/a><\/div>\n<p>PromptSpy is also equipped to capture victim biometric data to replay authentication gestures, such as a lock screen PIN or a pattern, to regain access to a compromised device. On top of that, it&#8217;s capable of preventing uninstallation by making use of an \u00abAppProtectionDetector\u00bb module that identifies the on-screen coordinates of the \u00abUninstall\u00bb button and serves an invisible overlay just over the button to block a victim&#8217;s touch events and give the impression that the button is unresponsive.<\/p>\n<p>\u00abWhile PromptSpy initializes using hardcoded default infrastructure and credentials, the malware is designed with high operational resilience, allowing adversaries to rotate critical components at runtime without redeploying the PromptSpy payload,\u00bb Google said.<\/p>\n<p>\u00abSpecifically, the malware&#8217;s command-and-control (C2) infrastructure, including the Gemini API keys and the VNC relay server, can be updated dynamically via the C2 channel. This configuration model demonstrates the developers anticipated defensive countermeasures and engineered the backdoor to maintain presence even if specific infrastructure endpoints are identified and blocked by defenders.\u00bb<\/p>\n<p>Google said it took steps against PromptSpy by disabling all assets related to the malicious activity. No apps containing the malware have been discovered on the Play Store. Some other cases of Gemini-specific abuse spotted by Google are listed below &#8211;<\/p>\n<ul>\n<li>A suspected China-nexus cyber espionage group dubbed <a href=\"https:\/\/thehackernews.com\/2026\/02\/google-disrupts-unc2814-gridtide.html\">UNC2814 prompted Gemini by asking it to assume the role of a network security expert to trigger persona-driven jailbreaking and support vulnerability research into embedded device targets, including TP-Link firmware and Odette File Transfer Protocol (OFTP) implementations.<\/li>\n<li>The North Korean threat actor known as APT45 (aka Andariel and Onyx Sleet) sent \u00abthousands of repetitive prompts\u00bb that recursively analyze different CVEs and validate proof-of-concept (PoC) exploits.<\/li>\n<li>A Chinese hacking group known as APT27 leveraged Gemini to speed up the development of a fleet management application with an aim to likely manage an operational relay box (ORB) network.<\/li>\n<li>A cluster of Russia-nexus intrusion activity targeted Ukrainian organizations to deliver AI-enabled malware dubbed CANFAIL and LONGSTREAM, both of which use LLM-generated decoy code to conceal their malicious functionality.<\/li>\n<\/ul>\n<p>Threat actors have also been found experimenting with a specialized GitHub repository named \u00ab<a href=\"https:\/\/github.com\/tanweai\/wooyun-legacy\">wooyun-legacy<\/a>\u00bb that&#8217;s designed as a Claude code skill plugin featuring over 5,000 real-world vulnerability cases collected by the Chinese vulnerability disclosure platform WooYun between 2010 and 2016.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJzJCFsazf55StUGcYp7NPuiozDmCXzFylr4U13gHpmSl4DmoKYB2XxuWniZu_eDX9zR-EJMdynNOEwvKfVGPCe4OwXqvYwOVUTctcgZtY47oZLQCZUEtNkl695oL8QkmpzeoAr-_ObLCUhgt5v2aQNm937b2W7ueYZyRPCXQNJEqZ18hR5o220ZXSnMNc\/s1700-e365\/ai-q2-fig8.max-2100x2100.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJzJCFsazf55StUGcYp7NPuiozDmCXzFylr4U13gHpmSl4DmoKYB2XxuWniZu_eDX9zR-EJMdynNOEwvKfVGPCe4OwXqvYwOVUTctcgZtY47oZLQCZUEtNkl695oL8QkmpzeoAr-_ObLCUhgt5v2aQNm937b2W7ueYZyRPCXQNJEqZ18hR5o220ZXSnMNc\/s1700-e365\/ai-q2-fig8.max-2100x2100.png\" alt=\"\" border=\"0\" data-original-height=\"1436\" data-original-width=\"2048\"\/><\/a><\/div>\n<p>\u00abBy priming the model with vulnerability data, it facilitates in-context learning to steer the model to approach code analysis like a seasoned expert and identify logic flaws that the base model might otherwise fail to prioritize,\u00bb Google explained.<\/p>\n<p>Elsewhere, a suspected China-aligned threat actor is said to have deployed agentic tools like Hexstrike AI and Strix in an attack targeting a Japanese technology firm and a major East Asian cybersecurity platform to conduct automated discovery with minimal human oversight.<\/p>\n<p>Google also said it continues to see information operations (IO) actors from Russia, Iran, China, and Saudi Arabia using AI for common productivity tasks like research, content creation, and localization, even as it called out China-affiliated threat activity from UNC6201 that involved the use of a publicly available Python script to automatically register and immediately cancel premium LLM accounts.<\/p>\n<p>\u00abThis process highlights the methods adversaries leverage to procure high-tier AI capabilities at scale while insulating their malicious activity from account bans,\u00bb GTIG pointed out.<\/p>\n<p>\u00abThreat actors now pursue anonymized, premium-tier access to models through professionalized middleware and automated registration pipelines to illicitly bypass usage limits. This infrastructure enables large-scale misuse of services while subsidizing operations through trial abuse and programmatic account cycling.\u00bb<\/p>\n<p>Another China-linked activity flagged by Google originates from UNC5673 (aka TEMP.Hex), which has employed various publicly available commercial tools and GitHub projects to likely facilitate scalable LLM abuse.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The findings overlap with <a href=\"https:\/\/www.chinatalk.media\/p\/how-to-buy-cheap-claude-tokens-in\">recent<\/a>\u00a0<a href=\"https:\/\/www.scmp.com\/tech\/tech-trends\/article\/3353002\/shadow-apis-how-chinese-developers-bypass-restrictions-access-claude-and-gemini\">reports<\/a> about a thriving grey market of API relay platforms that allow local developers in China to illicitly access Anthropic Claude and Gemini. These relay or transfer stations route access to these AI models through proxy servers that are hosted outside mainland China. The services are advertised on Chinese online marketplaces Taobao and Xianyu.<\/p>\n<p>In a study <a href=\"https:\/\/arxiv.org\/abs\/2603.01919\">published<\/a> in March 2026, academics from the CISPA Helmholtz Center for Information Security found 17 shadow APIs that claim to provide access to official model services without regional limitations via indirect access. A performance evaluation of these services uncovered evidence of model substitution, exposing AI applications to unintended safety risks.<\/p>\n<p>\u00abOn high-risk medical benchmarks like MedQA, the accuracy of the Gemini-2.5-flash model drops precipitously, from 83.82% with the official API to approximately 37.00% across all examined shadow APIs,\u00bb the researchers said in the paper.<\/p>\n<p>What&#8217;s more, the proxy services can capture every prompt and response that passes through their servers, providing the operators with unlawful access to a goldmine of data that could then be used for fine-tuning models and conducting\u00a0illicit knowledge distillation.\u00a0<\/p>\n<p>In recent months, AI environments have also become the target of adversaries like\u00a0TeamPCP (aka UNC6780), exposing developers to supply chain attacks and enabling attackers to burrow deeper into compromised networks for follow-on exploitation.<\/p>\n<p>\u00abFor example, threat actors with access to an organization\u2019s AI systems could leverage internal models and tools to identify, collect, and exfiltrate sensitive information at scale or perform reconnaissance tasks to move deeper within a network,\u00bb Google said. \u00abWhile the level of access and particular use depends heavily on the organization and the specific compromised dependency, this case study demonstrates the broadened landscape of software supply chain threats to AI systems.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first&hellip;<\/p>\n","protected":false},"author":1,"featured_media":874,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[439,394,1600,65,338,816,126],"class_list":["post-873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-2fa","tag-bypass","tag-develop","tag-exploitation","tag-hackers","tag-mass","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=873"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/873\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/874"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}