Google’s Threat Intelligence Group has identified a new experimental malware, PROMPTFLUX. This malware has the ability to ask the large language model Gemini to rewrite its code. One version of this malware was designed to rewrite itself every hour.
Why Rewriting?
The purpose is to make it hard for security software to detect. Security tools often rely on recognizing known patterns in malicious code. If malware keeps changing, it becomes a moving target. While this does not make it invisible to all detection tools, it complicates certain types of detection.
The Early Stages of PROMPTFLUX
When Google discovered PROMPTFLUX, it was still in development. Researchers had not yet seen it successfully compromise any device or network. Google moved to disable assets linked to this activity.
The Evolution of AI in Cyberattacks
A significant development followed this discovery. Google documented instances where AI was used during live malware attacks. An Android backdoor, for example, showed AI helping malware understand phone activity and making decisions. This indicates the potential direction of AI-powered malware.
How PROMPTFLUX Operates
PROMPTFLUX was a VBScript-based project, uncovered by Google in June 2025. It included a module termed the “Thinking Robot,” which contacted Gemini for new obfuscation methods, enhancing its stealth. Another variation instructed Gemini to rewrite its code hourly while keeping functional parts intact, posing challenges for security systems.
The Implications for Antivirus Software
AI-modified malware doesn’t render antivirus software useless. Signature detection is still an integral part of cybersecurity. Advanced security tools also use real-time monitoring, behavioral analysis, and machine learning to spot new threats. Changing code alone doesn’t ensure invisibility, as security systems can detect suspicious actions.
From Experimental to Live Attacks: PROMPTSTEAL
While PROMPTFLUX was experimental, PROMPTSTEAL marked a shift. Google found this AI-powered malware used by APT28, a Russian group, in Ukraine. Unlike PROMPTFLUX, PROMPTSTEAL queried a large language model to execute tasks, such as gathering data from specific folders and sending it back to attackers.
PROMPTSPY: AI Reacting to Phone Interactions
In May 2026, Google detailed the Android backdoor PROMPTSPY, which employed AI to understand and interact with phone interfaces. The malware could manipulate phone functions to remain installed. Google acted against those responsible, ensuring no apps on Google Play contained PROMPTSPY at the time.
Trends in AI and Malware Automation
Google’s recent reports highlight an ongoing trend towards more automation in malware development. For instance, attackers have used AI to handle large parts of cyber operations, reducing the need for human intervention. This shift is concerning as it speeds up attack processes.
Addressing the Growing Challenge
Today’s cybersecurity landscape already deals with vast amounts of malware. According to AV-TEST, daily registrations of malware and unwanted applications exceed 450,000. This volume illustrates the challenge for security firms to rely solely on file recognition.
Protecting Yourself Against Advanced Malware
Defending yourself doesn’t require deep technical understanding. You can take several key steps to protect your devices:
- Choose antivirus software with behavior monitoring.
- Keep real-time and cloud protection on.
- Enable automatic software updates.
- Avoid following online commands blindly.
- Heed warnings from browsers and computers.
- Download apps and extensions cautiously.
- Use password managers and multifactor authentication.
- Maintain separate backups for crucial data.
- Act swiftly if you suspect malware infection.
The Road Ahead
PROMPTFLUX showcases the evolving threat landscape. AI allows attackers to alter malware during runtime, adding complexity to detection and prevention efforts. While antivirus software remains crucial, attackers continue leveraging AI to automate and enhance efficiency. Security must focus on layers of protection and prompt response to threats.
