ThinkPatternGet the app
Story
TECHNOLOGY · NOV 5, 2025

Google Warns of New Operational Phase of AI-Enabled Malware

Google Threat Intelligence Group detected adaptive malware using large language models to rewrite code in real time and evade security software.

The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse where cyber adversaries integrate large language models (LLMs) into live operations to create adaptive malware. This "just-in-time AI" allows malware to dynamically rewrite its own source code and alter behavior during execution, enabling it to obfuscate its presence and evade traditional signature-based antivirus detections.

GTIG identified several specific strains, including PromptFlux, a VBScript dropper that abuses the Google Gemini API to regenerate code, and PromptSteal, a Python data miner. The group attributed PromptSteal to the Russian state-sponsored actor APT28, which utilized the Hugging Face API and Alibaba Group's Qwen model to execute commands during attacks in Ukraine. Other detected families include PromptLock ransomware and the QuietVault credential stealer.

Beyond malware, Google warned that state-sponsored groups from China, Iran, and North Korea are using social engineering pretexts, such as posing as students in "capture-the-flag" competitions, to bypass AI safety guardrails. While Google has worked with DeepMind to strengthen security frameworks, some independent researchers, including Marcus Hutchins and Kevin Beaumont, criticized the findings, claiming the malware samples were poorly constructed and lacked significant real-world impact.


Reported across 16 outlets
Actors
Alibaba GroupGoogle DeepMind

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play