Google's Threat Intelligence Group (GTIG) has reported that various malware strains are now utilizing large language models to generate or obfuscate attack code. The North Korean hacker group UNC1069, also known as Masan, has been identified as exploiting the Gemini model to probe cryptocurrency wallet data and craft phishing scripts aimed at stealing digital assets. In response, Google has blocked the associated accounts and enhanced security monitoring of its models. The report highlights the increasing use of AI in the operational phases of crypto theft and cyberattacks.