ZeroHour
Malware

PROMPTSTEAL

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection

Morphisec warns AI-driven malware like PROMPTFLUX rewrites its code hourly via the Gemini API, eroding signature-based detection.

Morphisec analysts reviewed Google's late-2025 disclosure of PROMPTFLUX, an experimental dropper that queried the Gemini API roughly hourly and generated more than 70 obfuscated variants in under four hours. Related samples PROMPTSTEAL, PromptLock, and BlackMamba use LLMs to generate Windows commands or mutate payloads at runtime. The report argues signature-based controls lose value when every copy differs and recommends prevention-first execution controls and behavior-based detection.

Cyber Security News · 8h agoMalware in the wild 2 sources

AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection

Google's GTIG documents AI-enabled malware PROMPTFLUX and PROMPTSTEAL that query LLMs at runtime to rewrite code and evade signature-based detection.

Google Threat Intelligence Group documented 'just-in-time' AI-enabled malware that queries language models during execution. PROMPTFLUX, an experimental VBScript dropper, calls the Gemini API to regenerate and obfuscate its own source code and writes variants to the Windows Startup folder for persistence. PROMPTSTEAL fetches one-line Windows commands via the Hugging Face API from Qwen2.5-Coder-32B-Instruct to collect files and system information, which Google linked to APT28 activity targeting Ukraine. The article argues signature-based defenses retain value but defenders should prioritize behavioral detection and deterministic prevention controls.

GBHackersupdated · 8h agofirst · 10h agoMalware in the wild 2 sources