AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection
Morphisec warns AI-driven malware like PROMPTFLUX rewrites its code hourly via the Gemini API, eroding signature-based detection.
Morphisec analysts reviewed Google's late-2025 disclosure of PROMPTFLUX, an experimental dropper that queried the Gemini API roughly hourly and generated more than 70 obfuscated variants in under four hours. Related samples PROMPTSTEAL, PromptLock, and BlackMamba use LLMs to generate Windows commands or mutate payloads at runtime. The report argues signature-based controls lose value when every copy differs and recommends prevention-first execution controls and behavior-based detection.
55