Low-confidence report
This report is hidden because you're viewing high- and medium-confidence reports only. It isn't counted in the scores you're seeing.
Leaderboard / Case No. FB-2026-09-08-google-basin-castle-espionage
A China-linked espionage group used Gemini to pick high-profile targets, translate spear-phishing lures, add evasion and obfuscation to its custom malware, and fix PowerShell errors during post-intrusion domain discovery.
Score breakdown
| Component | Value | Reasoning |
|---|---|---|
| Sentence-Years | 1 | 18 USC 1030(a)(2)(C) |
| × Contribution | 0.5 | Wrote the content: Google says the group supplied source code to Gemini "to implement evasion and obfuscation tactics and consolidate foothold (e.g., dynamic API resolution via PEB parsing, rolling XOR encryption of C2 IP addresses)" and used it to "generate, refine, and localize lure content"; humans ran the intrusions, so this is written content. |
| × Blast Radius | 1 | Third party: The targets are unnamed high-profile individuals reached by spear-phishing; no government victim is named, so blast radius is the conservative third party. |
| × Legal status | 1 | Crime. |
| + Tradecraft | 2 | Gemini implemented the malware's evasion and obfuscation (dynamic API resolution, encrypted C2 addresses), which is covering its tracks. |
| + Guardrails | 0 | Guardrails intact: Google's report describes no jailbreak; it says the activity triggered Gemini's safety responses and Google disabled the associated assets, so guardrails are scored intact. |
| + Dwell Time | 0 | The report gives no dates for the activity, so date_precision is before with the report's publication date (2026-09-08); dwell is counted from that latest possible date (0 days) and never inflated. Google found the misuse itself. |
| Total | 2.5 |
Charges the human could face
18 USC 1030(a)(2)(C)Up to 1 year