Researchers at Google's Threat Intelligence Group have found that attackers are developing malware capable of using large language models to modify itself dynamically.
An experimental malware variant called PROMPTFLUX, discovered by GTIG, can alter its own code to evade security detection systems. This development represents an important escalation in cybersecurity threats, as it demonstrates how generative AI capabilities are being weaponized.
Tools like PROMPTFLUX dynamically generate malicious scripts, obfuscate their own code to evade detection, and leverage AI to create harmful functions on demand. This "just-in-time" approach indicates movement toward more autonomous and adaptive malware, according to researchers.
PROMPTFLUX functions as a Trojan that communicates with Google's Gemini AI model via API to learn self-modification techniques that help it avoid detection.
Google noted that PROMPTFLUX samples appear to be in development stages, with incomplete features and mechanisms limiting API usage. Importantly, this malware has not yet been observed infecting systems in active operations, and Google states the current version cannot compromise networks or devices. The company has disabled associated assets.
GTIG indicates the malware connects to financially motivated actors and warns of an emerging underground marketplace for illicit AI tools that could enable less experienced threat actors to launch attacks. State-sponsored groups from North Korea, Iran, and China are reportedly experimenting with AI tools to strengthen their capabilities.
In response, GTIG developed a conceptual framework for securing AI systems, and Google introduced an AI agent called Big Sleep designed to identify software vulnerabilities โ suggesting AI will play dual roles in cybersecurity offense and defense.

