Scope: what this does not show
Covers provider reports from February 2024 to January 2025, based on activity the providers could see on their own services; actors using other or self-hosted models were outside this view.
Superseded: Replaced by a newer measurement of the same thing. Kept for the trend.
Evidence
Feb 14, 2024
Microsoft and OpenAI report state-backed hackers using LLMs as a productivity tool
Microsoft and OpenAI saw five state-affiliated actors use LLMs for support tasks and no novel AI-enabled techniques.
Jan 29, 2025
Google finds government-backed hackers using Gemini for support tasks, not novel capabilities
Google saw productivity gains but no novel capabilities in government-backed actors’ use of Gemini.
How it relates to other findings
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- Malware that queries a language model during execution to generate commands has been used in live operations, including by a state-backed group; self-rewriting variants have been seen only in testing. supersedes this findingGTIG’s November 2025 update reports novel, model-using malware in operations, replacing its January 2025 finding of productivity-only use.
Status history
- 2024-02-14ReportedMicrosoft and OpenAI report productivity-level use by state-affiliated actors. · record
- 2025-01-29CorroboratedGoogle independently reports the same pattern in Gemini use. · record
- 2025-11-05SupersededGTIG reports malware that uses LLMs during execution in live operations, a capability beyond productivity use. · record