Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Malware - AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks
Malware Artificial Intelligence Attacks Latest News News & Analysis Security

AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks

Dilki RathnayakeBy Dilki RathnayakeNovember 7, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
AI Malware Google
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Threat actors aren’t just using AI to write better phishing emails anymore; they’re building malware that thinks for itself. 

Google’s Threat Intelligence Group (GTIG) has identified a new phase in cyber operations where attackers are embedding large language models (LLMs) directly into their malware. The finding is a shift from AI as a productivity booster to AI as an active, adaptive weapon. 

Malware That Rewrites Itself 

In what Google calls the first example of “just-in-time AI,” GTIG discovered malware families like PROMPTFLUX and PROMPTSTEAL that use AI during execution to generate new code, hide their tracks, and even change behavior mid-run. 

PROMPTFLUX, for example, uses Google’s Gemini API to rewrite its own VBScript code, a move designed to evade antivirus detection by constantly mutating its form. GTIG researchers found evidence of a “Thinking Robot” module inside the code, programmed to query Gemini for fresh obfuscation techniques. The goal: evolve before defenders can catch up. 

This is an early but significant indicator of where threats are headed, Google said. 

State Actors and Social Engineering 

It’s not just experimental malware. State-backed groups from Russia, Iran, North Korea, and China are misusing AI tools (including Gemini and other open models) to supercharge the full attack lifecycle. That means faster reconnaissance, more convincing phishing, smarter command-and-control setups, and improved data theft. 

In one case, Russian group APT28 deployed PROMPTSTEAL, a data miner that queries a language model on Hugging Face to generate system reconnaissance commands on the fly. Meanwhile, Chinese-linked actors used AI to build phishing lures, create fake capture-the-flag (CTF) research prompts to bypass safety systems, and even research cloud exploitation techniques. 

Iranian actor TEMP.Zagros went as far as posing as a student or academic to trick Gemini into assisting with custom malware development, accidentally exposing parts of their own infrastructure in the process. 

A Growing Black Market 

The underground market for illicit AI tools has also matured. GTIG found AI-enabled services being sold in 2025 that promise everything from deepfake creation to automated phishing kits and “malware-as-a-service” generation. The sales pitches look eerily similar to legitimate AI marketing: boosting productivity, improving workflows just for crime. 

Even low-skilled attackers can now buy or rent these AI-enhanced tools, lowering the barrier to entry and increasing attack volume. 

Google’s Response 

Google says it has disabled the accounts linked to this malicious activity and fed the intelligence back into Gemini’s defences. The company is also tightening its classifiers and safety systems to help models refuse similar misuse in the future. 

It adds that it is developing AI boldly but responsibly and emphasized its Secure AI Framework (SAIF) as a foundation for safer model design. Google DeepMind is also running “red team” evaluations that stress-test models against indirect prompt injection and abuse. 

Build Testing Methodologies That Assume AI-Powered Threats 

According to Michael Bell, Founder & CEO of Suzu Labs: “This is exactly what we’ve been warning about with the OWASP Top 10 for LLMs framework. PROMPTFLUX represents a shift from static malware signatures to adversarial AI that actively evades detection by rewriting itself in real-time.” 

Bell adds that the good news is that Google caught this while it’s still experimental. “But the bad news is that once this capability matures, traditional security tools that rely solely on pattern matching will be almost useless except to defend against basic script kiddies.” 

He says it’s crucial to build security testing methodologies that assume AI-powered threats from day one. “The underground marketplace for “AI tools purpose-built for criminal behavior” isn’t coming in the future; it’s already here, and most enterprises aren’t remotely prepared for what happens when attackers have the same AI capabilities defenders do.”  

Dilki Rathnayake
Dilki Rathnayake

Dilki Rathnayake is a cybersecurity content writer and the Managing Editor at Information Security Buzz, with a BSc in Cybersecurity and Digital Forensics. She is skilled in computer network security and Linux system administration. Dilki has also led awareness programs and volunteered for communities promoting best practices for online safety.

  • Dilki Rathnayake
    The new rules of war have no rules
  • Dilki Rathnayake
    Out of Office, Not Out of Mind: Staying Cyber-Smart Over the Holidays
  • Dilki Rathnayake
    The Real Purpose of the UK’s Online Safety Act: An Expert Explains
  • Dilki Rathnayake
    2025 ZeroFox Forecast: Dark Web, Ransomware, Gen AI & Beyond

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

When PUPs bite: Huntress uncovers “weaponised” adware exposing 25,000+ systems

April 16, 20262 Mins Read

Fake Tech Support Scams Deliver Advanced Command-and-Control Malware

March 5, 20262 Mins Read

Americans Lost Over $20 million in ATM “Jackpotting” Attacks

February 24, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}