Google begins to analyse and scrape dark web
Google says it has started using AI agents to analyse and scrape the mostly unmapped dark web for cybersecurity threats.
Agents will automatically visit scores of deep web hacker forums and imageboards, gathering intelligence on ongoing threats and potential targets, then report back with their findings.
The dark web is the portion of the Internet that runs on encrypted servers and requires specialised software, such as the Tor Browser, to access. It is often frequented by criminal black markets and cybercriminals.
Using Gemini, Google says it is now analysing millions of dark web events daily, highlighting only threats relevant to partners’ business operations.
“To get teams the critical data they need to make quick, accurate decisions about rising threats, we’re introducing a new dark web intelligence capability,” it said in an announcement.
“The new dark web intelligence capability is positioned to change how organizations gain insight into some of the hardest-to-track threats and threat actors in the world.”
Companies that make use of the new dark web intelligence capability will see Gemini build a specific company profile and then warn security teams of any potential threats based on this profile.
This profile dynamically evolves as companies use and integrate intelligence, making sure threat highlighting remains relevant to operations at any given time.
Google says that the benefit of using AI agents is that they are able to contextualise what they’re analysing.
“Consider a scenario where an initial access broker posts on an underground forum that they’re selling active VPN access to a major European retailer with $15 billion in annual revenue,” it says.
“Since many legacy tools depend on exact keyword matches for your brand name, and the broker has intentionally avoided naming the victim, security teams aren’t alerted.”
Dark web intelligence would cross-reference the broker’s post with a company’s profile, matching revenue, geographic location, and specific portal types.
The final product is a relevant and accurate warning sent to an organisation before an actor can even begin launching an attack or selling an attack vector.
“In previous roles, I’ve leveraged several dark web tools and found they averaged over 90% false positives,” said Michael Kosak, director of threat intelligence for password management firm LastPass.
“The new dark web intelligence flips this, filtering noise and connecting dots that no human analyst could see in time.”
Kosak says the difference in warning times is like being able to put out a house fire before the first match is struck.
Google Threat Intelligence told The Register that Gemini AI agents were now crawling through “every single post” on the dark web.
“We’re seeing anywhere from eight to 10 million events a day, and we’re able to distill that down in very short throughput,” said Brandon Wood, Google Threat Intelligence product manager.
The company claims its Threat Intelligence can analyse millions of daily external events with a 98% accuracy.