Google Threat Intelligence Group (GTIG) released a report on Monday stating that a threat actor successfully used artificial intelligence (AI) to develop a usable zero-day vulnerability. This is considered the first time this technology has been practically used in such attacks, marking a shift in AI's role in cybercrime from theory to reality.

According to GTIG, the operation aimed to launch a large-scale exploitation event but ultimately failed—Google discovered the activity before the vulnerability was weaponized. GTIG then notified the developer of the vulnerability and has released a patch to eliminate the potential threat. Researchers also stated that they do not believe a tool named "Mythos" was involved in this development process.

John Hultquist, chief analyst at GTIG, noted in an email to Cybersecurity Dive: "AI can review underlying logic, context, and processes at scale in code to find vulnerabilities. It can also be used to build usable exploit code, which is often a major hurdle in attacks."

This incident highlights a trend where state-linked and economically driven threat groups increasingly use AI to expand and accelerate hacking attacks and exploit flaws in widely used applications. GTIG researchers warned that they have observed multiple other attempts to develop vulnerabilities using AI and expect more operations employing different models in the future.

According to the GTIG report, threat groups linked to North Korea and China have shown strong interest in using AI to discover vulnerabilities. For example, the North Korean hacking group tracked as APT45 has used AI to analyze large numbers of vulnerabilities through thousands of repeated prompts and verify proof-of-concept exploit code.

In a recent case involving criminals, a group of hackers jointly planned a large-scale exploitation operation. GTIG stated that a zero-day vulnerability was embedded in a Python script, allowing hackers to bypass two-factor authentication on a widely used open-source system management tool. Researchers worked with the vendor to disclose the vulnerability and disrupt the operation.

The report comes after an unidentified hacker attempted to use widely used AI tools, including Claude,to breach a water utility company in Mexico.