Newsclip — Social News Discovery

Business

AI Malware Is Evolving Beyond Detection

September 22, 2026
  • #Cybersecurity
  • #Artificialintelligence
  • #Malware
  • #Techsecurity
  • #Digitalthreats
  • #Aiattack
3 views•0 comments
AI Malware Is Evolving Beyond Detection

When Malware Learns to Adapt

What started as experimental code has now become a stark reminder of how quickly cyber threats can evolve. Google's Threat Intelligence Group recently identified a malware strain called PROMPTFLUX that leverages the Gemini AI model to rewrite its own code every hour. This isn't just another variant of existing malware—it marks a significant turning point in how attackers are approaching digital warfare.

How It Works

PROMPTFLUX was discovered in June 2025, but what made it particularly alarming wasn't its initial form—it was its ability to ask AI models like Gemini for help while running. One version of the malware was designed to request new obfuscation techniques every hour, making it nearly impossible for security software to track it using traditional signature-based methods.

"We're seeing a shift from static code to adaptive systems," says my colleague at Google's Threat Intelligence Group. "Malware is no longer just reactive—it's proactive."

The Thinking Robot component of PROMPTFLUX was the most advanced feature, allowing it to generate new versions of itself that preserved functionality while appearing completely different to detection tools.

Why This Matters

Security professionals have long known that malware can mutate and change its appearance to evade detection. However, PROMPTFLUX introduces a new layer of complexity: the malware isn't just changing—it's learning how to change. By integrating AI into its core operations, it makes itself a moving target in real time.

It's important to note that PROMPTFLUX was still in development when Google found it, and researchers had not yet observed it successfully compromising any devices. But the implications of what it could do were clear.

The Next Evolution: Live Attacks

Google has since documented cases where AI-powered malware has been used during live attacks. In one notable case, an Android backdoor called PROMPTSPY was discovered in May 2026 that could use AI to understand what is happening on a phone and decide how to respond. This represents a fundamental shift—malware isn't just reacting to commands anymore; it's interpreting its environment.

From Experimentation to Operational Use

The transition from experimental malware like PROMPTFLUX to operational tools such as PROMPTSTEAL is particularly telling. Google identified the Russian government-backed group APT28 using PROMPTSTEAL against targets in Ukraine. Unlike PROMPTFLUX, which focused on self-modification, PROMPTSTEAL used AI models to generate Windows commands that could gather sensitive data and exfiltrate it back to attacker infrastructure.

This marks a critical moment in the evolution of cyber warfare. AI is no longer just a tool for attackers—it's becoming an integral part of the attack process itself.

What This Means for Security

Traditional antivirus software relies heavily on known signatures to identify malware. But as Google's research shows, AI-powered malware can change its appearance so rapidly that even behavioral analysis tools may struggle to keep up. However, I want to emphasize that this doesn't make antivirus software obsolete.

  • Signature-based detection remains a crucial first line of defense
  • Behavioral monitoring and cloud-delivered protection continue to be essential
  • Real-time threat intelligence can flag unusual activity even if the code changes

The key is that these layers must work together. As we've seen with recent reports, attackers are not only using AI for obfuscation but also for automating entire operations.

Real-World Examples of AI Automation in Cyberattacks

In one striking example, Google reported that a financially motivated attacker used an AI coding chatbot and agent instructions to plan, build, and execute a mass credential-harvesting campaign in under six hours. The system managed vulnerability scanning and troubleshooting while the attack was underway—something that would have required human intervention just a few years ago.

This automation doesn't mean fully autonomous AI attacks are common yet. But it does suggest we're moving closer to a world where cybercriminals can scale their operations with minimal human oversight.

The Growing Volume of Malware

AI arrives in an environment already overwhelmed by malware. Independent security firm AV-TEST registers over 450,000 new malicious programs daily, not all unique, but certainly representing a massive volume that traditional detection systems struggle to manage.

The FBI reported nearly $21 billion in cyber-enabled crime losses during 2025—a 26% increase from the previous year. These numbers underscore how much money criminals stand to gain when they make attacks easier to execute.

Protecting Yourself in an AI-Driven Threat Landscape

As we move forward, protection strategies must evolve accordingly. The best defense remains layered and proactive:

  1. Use antivirus software with behavior monitoring — Look for solutions that can detect unusual activity even when malware changes appearance.
  2. Keep real-time protection enabled — Ensure cloud-delivered threat intelligence is always active.
  3. Update software regularly — Patch vulnerabilities before they can be exploited.
  4. Avoid pasting unknown commands — Be wary of any instruction that asks you to run terminal commands from websites.
  5. Pay attention to warnings — Security alerts should never be dismissed lightly.
  6. Download apps carefully — Trust only verified sources for mobile applications and browser extensions.
  7. Use strong authentication — Password managers, MFA, and passkeys provide better protection than passwords alone.
  8. Backup your important files — Ransomware attacks can be devastating if backups aren't in place.
  9. React quickly when something goes wrong — If you suspect infection, disconnect from the internet and run a full scan immediately.

Final Thoughts

AI malware isn't here to replace current threats—it's here to redefine them. As we see with PROMPTFLUX, PROMPTSTEAL, and PROMPTSPY, the threat landscape is shifting toward systems that can adapt, learn, and evolve while under attack. This isn't a sign that we've lost the battle against cybercrime, but rather a call to action for all stakeholders to prepare for an increasingly intelligent and autonomous threat environment.

What concerns me most is how fast this evolution is happening. We're not just dealing with malware that changes—it's learning, adapting, and potentially outsmarting our defenses before we even realize what we're up against.

Key Facts

  • Primary malware strain discovered: PROMPTFLUX
  • AI model used for code rewriting: Gemini
  • Discovery date: June 2025
  • Malware type: VBScript-based
  • Rewrite frequency: Every hour
  • First live attack using AI malware: PROMPTSPY
  • Attack group behind PROMPTSTEAL: APT28
  • AI model used in PROMPTSTEAL: Qwen2.5-Coder-32B-Instruct

Background

Google's Threat Intelligence Group identified experimental malware called PROMPTFLUX that uses the Gemini AI model to rewrite its own code every hour, marking a significant evolution in cybersecurity threats. This malware was discovered in June 2025 and demonstrated adaptive capabilities by asking AI models for new obfuscation techniques. The discovery signaled a shift from static code to adaptive systems in malware, where the malware learns how to change rather than simply mutating. Subsequent research documented live attacks using AI-powered malware such as PROMPTSPY and PROMPTSTEAL, showing how attackers are beginning to use AI for real-time decision-making and automation of cyber operations.

Quick Answers

What is PROMPTFLUX malware?
PROMPTFLUX is experimental malware discovered by Google's Threat Intelligence Group that uses the Gemini AI model to rewrite its own code every hour, making it difficult for security software to detect using traditional signature-based methods.
When was PROMPTFLUX discovered?
PROMPTFLUX was discovered in June 2025 by Google's Threat Intelligence Group.
What AI model does PROMPTFLUX use?
PROMPTFLUX uses the Gemini AI model to rewrite its own code and generate new obfuscation techniques every hour.
How often does PROMPTFLUX rewrite its code?
PROMPTFLUX rewrites its code every hour while preserving functionality, making it difficult for detection tools to track it.
What is PROMPTSPY malware?
PROMPTSPY is an Android backdoor discovered in May 2026 that uses AI to understand what is happening on a phone and decide how to respond, representing a fundamental shift from reactive to interpreting malware.
Who used PROMPTSTEAL malware?
PROMPTSTEAL was used by the Russian government-backed group APT28 against targets in Ukraine, marking the first observation of malware querying a large language model while deployed in live operations.
What is the main concern about AI-powered malware?
The main concern is that AI-powered malware can change its appearance so rapidly that traditional detection methods may struggle to keep up, making it a moving target for security software.
How does PROMPTSTEAL differ from PROMPTFLUX?
PROMPTSTEAL queries the Qwen2.5-Coder-32B-Instruct model through Hugging Face to generate Windows commands for data gathering and exfiltration, whereas PROMPTFLUX rewrites its own code every hour using Gemini.

Frequently Asked Questions

What makes PROMPTFLUX malware significant?

PROMPTFLUX is significant because it represents a shift from static malware to adaptive systems that can learn how to change, making detection more difficult than traditional mutation-based approaches.

How does AI in malware affect cybersecurity?

AI in malware allows for real-time adaptation and decision-making during attacks, making traditional signature-based detection methods less effective as the malware becomes a moving target.

What are the implications of PROMPTSPY discovery?

PROMPTSPY shows how AI malware can interpret device interfaces and react to user environments, representing a major advancement from pre-programmed instructions to adaptive behavior.

Source reference: https://www.foxnews.com/tech/ai-malware-rewrite-itself-evade-detection

Comments

Sign in to leave a comment

Sign In

Loading comments...

More from Business