Google discovers AI malware that uses Gemini to alter code and escape detection.

Google discovers AI malware that uses Gemini to alter code and escape detection.

Google’s Threat Intelligence Group has discovered a new type of experimental malware named PROMPTFLUX. This malware is intriguing because it has the ability to instruct an AI model, called Gemini, to continuously rewrite its code. One version of PROMPTFLUX was designed to do this every hour. But why is that important? Well, the constant rewriting aims to make it more challenging for security software to identify it.

Security tools typically search for recognizable patterns in malicious code, but if that code keeps changing, it becomes a more elusive target. While this doesn’t immediately mean it can evade all security measures, it complicates detection efforts.

Here’s where things get a bit more nuanced. When Google first spotted PROMPTFLUX, it was still under development. Researchers hadn’t yet observed it successfully compromising devices or networks, and Google took measures to disable anything linked to this activity.

What really piqued my interest, though, is what came next. Google has now documented instances where malware utilized AI during real-time attacks. They even found an Android backdoor that employs AI to assess what’s occurring on a phone and decide on actions. This gives us a glimpse into the future of malware.

Understanding How AI-Powered Malware Functions

PROMPTFLUX is a malware variant based on VBScript that Google identified in June 2025. Its standout feature was dubbed the “Thinking Robot,” which allowed it to reach out to Gemini for new techniques to disguise itself from security systems. Google later found several variations of PROMPTFLUX, one of which included directions for Gemini to completely rewrite the malware’s source code every hour while keeping the core functions intact. This poses significant challenges for security defenders: if one version is detected, a new version could quickly be generated to continue its malicious activities.

Google characterized PROMPTFLUX as an early instance of “just-in-time” AI embedded within malware. This means that instead of relying solely on pre-programmed functions, it has the ability to seek assistance from an AI model as it operates.

Does This Make Antivirus Software Ineffective?

The answer is no, but it’s a bit more complicated. You might hear claims that AI malware can just change its facade and bypass antivirus solutions entirely, but the reality here involves several intricacies. Signature detection remains fundamental in cybersecurity. Security software can still catch the recognizable digital fingerprints of known malware and block them efficiently.

Moreover, modern antivirus solutions like Microsoft Defender go beyond mere signature comparisons. They also employ real-time monitoring, behavioral analysis, and heuristic protection, alongside cloud-based defenses and machine learning to spot new threats that may not match existing signatures.

Thus, mere code alteration won’t instantly render malware invisible. Security tools could still flag suspicious behavior once the malware attempts to execute harmful tasks. While PROMPTFLUX is concerning because it complicates certain detection methods, it doesn’t mean modern antivirus systems lose all efficacy.

The Emergence of PROMPTSTEAL

PROMPTFLUX remained theoretical, but PROMPTSTEAL marked a pivotal shift. Google has linked PROMPTSTEAL to the Russian-backed group APT28, which deployed it against targets in Ukraine. This represented the first instance of malware utilizing a large language model during active operations.

PROMPTSTEAL functions differently compared to PROMPTFLUX. It connects with the Qwen2.5-Coder-32B-Instruct model via Hugging Face, generating Windows commands that it can carry out. These commands allow it to collect data from computers and retrieve documents from various directories. The collected information is then sent back to the attackers’ servers, marking a significant change where the AI model becomes integral to the malware’s operation.

Introducing PROMPTSPY

The most recent development is PROMPTSPY, identified by Google in May 2026, following its initial detection by ESET. This Android backdoor features an AI component called GeminiAutomationAgent, which can relay information about the screen contents of an infected device to Gemini. It even uses responses from Gemini to help navigate around the phone’s interface.

In simpler terms, this malware can utilize AI to interpret parts of the screen and figure out how to act. Google discovered that PROMPTSPY also has capabilities that make it harder to uninstall: it could create invisible overlays on the uninstall button, making it seem non-responsive. However, there is some reassurance for Android users, as no apps containing PROMPTSPY were found on Google Play when reported. Known variants are detectable by Google Play Protect, which is active by default on Android devices.

Google Sees Increased Automation Among Attackers

Google’s latest findings suggest a noticeable trend: attackers are shifting from basic AI prompts to more automated, agent-like AI processes. On September 8, 2026, the Google Threat Intelligence Group reported observing attackers leveraging AI to manage larger aspects of their operations with less reliance on human action.

One especially striking case involved a financially motivated attacker who infiltrated a company’s cloud systems and, using an AI chatbot, orchestrated a mass credential-harvesting operation in under six hours. This AI-driven system could also conduct vulnerability assessments and troubleshoot issues in real-time during the attack. Thousands of credentials were compromised.

Additionally, Google noted increased experimentation among attackers with automated reconnaissance and frameworks for managing stolen credentials. However, there’s a crucial caveat: Google has not yet seen fully autonomous exploit pipelines in action in the wild, meaning we haven’t reached the point where AI carries out every element of a cyberattack independently.

The Growing Malware Landscape

AI is emerging on top of an already significant malware issue. The independent security research group AV-TEST records over 450,000 new malicious software and potentially unwanted applications daily. This doesn’t imply that 450,000 distinct attacks happen every day, as many samples involve variations of existing threats.

Nonetheless, the high volume underscores why security firms can’t rely solely on visual recognition of malicious files. Meanwhile, the financial repercussions of cybercrime keep escalating. The FBI reported that Americans lost nearly $21 billion to cyber-enabled crimes in 2025, which is a 26% increase from the previous year. Though not all these losses can be traced back to AI-generated malware, they highlight the opportunities for criminals when technology simplifies their attacks.

How to Protect Yourself

You don’t need to be an expert in how AI can rewrite VBScript to safeguard yourself. The best strategy remains to make it more challenging for malware to access your devices and ensure that if something does get through, it won’t succeed easily.

1) Choose Antivirus Software with Behavioral Monitoring

Look for robust antivirus solutions equipped with real-time protection that can track behavior. This becomes crucial when malware alters itself enough that a conventional signature might not detect it. Efficient antivirus can monitor the actions of a program post-launch, and if it makes suspicious changes or attempts to modify system settings, another layer of detection can kick in.

2) Keep Real-Time and Cloud Protection Active

Security software won’t be effective if its strongest features have been disabled. For Windows users, ensure that Microsoft Defender’s behavior monitoring remains enabled as it is by default. Cloud protection is also pivotal in detecting new threats. If a website or prompt tells you to deactivate antivirus protections to proceed, resist the urge to comply; it’s often a trap.

3) Enable Automatic Software Updates

Keep your OS and browser up to date, as well as the software you often use. Attackers frequently exploit individuals operating outdated software with known vulnerabilities, and automatic updates can mitigate those risks without you having to keep up with every security note.

4) Avoid Running Commands from Unknown Sources

This warning cannot be overstated. Attackers are increasingly using fake CAPTCHA pages or misleading error messages to prompt victims to execute commands. Do not comply. Legitimate actions typically do not require command execution from the user’s end. Recently, many compromised sites have been involved in this tactic.

5) Take Browser Warnings Seriously

While security alerts can seem annoying when you’re in a rush to download something, don’t disregard them. Tools like Microsoft Defender SmartScreen can help assess sites and downloads for potential risks. If your browser raises suspicions or blocks a download, investigate before proceeding; never allow pressure to lower your defenses.

6) Be Cautious with Apps and Extensions

PROMPTSPY serves as a warning about the importance of where your apps originate. Google Play Protect routinely checks installed applications for harmful behaviors, including those downloaded from outside its ecosystem. Always enable this protection and be wary of sideloaded apps or browser extensions that aren’t from trusted sources.

7) Use a Password Manager and Enhance Account Security

A password manager can help generate unique passwords and offer phishing alerts. If a password doesn’t autofill like usual, re-check the website before entering it manually. Moreover, utilize multifactor authentication (MFA) whenever feasible, or even better, adopt passkeys where supported.

8) Backup Important Files

Ensure you have backups for anything irreplaceable, like family photos or crucial documents. Utilize cloud solutions or external drives that can be disconnected after use for recovery. Backups won’t stop malware from stealing data, but they can lessen the impact of ransomware or harmful software.

9) Know How to Respond If You Suspect Malware

Stay alert for unfamiliar programs or unexpected security alerts. If antivirus software disables itself or your browser behaves unusually, act promptly. Disconnect from the internet, run trusted scans, and if you suspect exposure of sensitive information, change your passwords using a different device. Monitor your financial accounts for suspicious activity, and take swift action if anything seems off.

Final Thoughts

PROMPTFLUX is a noteworthy example of evolving malware technology. For years, attackers have sought out ways to make detection tougher, and AI is just another tool in their arsenal. But it’s crucial not to view antivirus solutions as outdated; they adapt to new threats. The quick advancement of this technology is what concerns me. We’ve gone from experimental malware to live threats, and now we’re witnessing an increase in autonomous AI use in attacks. The message is clear: rely on multiple security measures, heed warnings, and maintain strong protective practices to fortify your devices.

As malware continues to evolve and adapt, do you believe that security companies can keep up, or are we facing a future where truly secure devices become harder to guarantee? Share your thoughts at CyberGuy.com.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News