+995 322 476 006[email protected]
CASESecurity ยท Education ยท Digital Innovation
Home
Aboutโ–พ
About CASECertificationVerify a CertificateOur TeamCASE NetworkCASE AnalyticaSuccess Stories
Coursesโ–พ
All CoursesCorporate Training
Servicesโ–พ
All ServicesCorporate Enquiry
Mediaโ–พ
NewsMedia Coverage
Blog
Resourcesโ–พ
Additional ResourcesPodcastE-booksSecurity BriefsFAQ
Contact
CASE
Security ยท Education ยท Digital Innovation

16 Years of experience teaching law enforcement, military, biggest corporations and students. Provider of innovative technologies, special training and security services.

COURSES
All programmesOnsite coursesOnline coursesMasterclassesCorporate training
SERVICES
Cyber & information securityData protection (DPO)Corporate trainingsDigital transformationAll services
CONTACT
+995 322 476 006[email protected]Tbilisi, Georgia ยท Pekini Ave. 30Contact usLOG IN โ†’
ยฉ 2026 CASE โ€” globalcase.org ยท All rights reservedTerms of usePrivacy policySitemap
HOME / SECURITY BRIEF / MALWARE IS NOW USING AI TO REWRITE ITS OWN CODE TO AVOID DETECTION

Malware Is Now Using AI to Rewrite Its Own Code to Avoid Detection

17 November 2025 ยท Breaking News

Researchers at Google's Threat Intelligence Group have found that attackers are developing malware capable of using large language models to modify itself dynamically.

An experimental malware variant called PROMPTFLUX, discovered by GTIG, can alter its own code to evade security detection systems. This development represents an important escalation in cybersecurity threats, as it demonstrates how generative AI capabilities are being weaponized.

Tools like PROMPTFLUX dynamically generate malicious scripts, obfuscate their own code to evade detection, and leverage AI to create harmful functions on demand. This "just-in-time" approach indicates movement toward more autonomous and adaptive malware, according to researchers.

PROMPTFLUX functions as a Trojan that communicates with Google's Gemini AI model via API to learn self-modification techniques that help it avoid detection.

Google noted that PROMPTFLUX samples appear to be in development stages, with incomplete features and mechanisms limiting API usage. Importantly, this malware has not yet been observed infecting systems in active operations, and Google states the current version cannot compromise networks or devices. The company has disabled associated assets.

GTIG indicates the malware connects to financially motivated actors and warns of an emerging underground marketplace for illicit AI tools that could enable less experienced threat actors to launch attacks. State-sponsored groups from North Korea, Iran, and China are reportedly experimenting with AI tools to strengthen their capabilities.

In response, GTIG developed a conceptual framework for securing AI systems, and Google introduced an AI agent called Big Sleep designed to identify software vulnerabilities โ€” suggesting AI will play dual roles in cybersecurity offense and defense.

SHARE
CATEGORIES
AllBreaking News
SUBSCRIBE

Get the weekly brief in your inbox.