Google’s Threat Intelligence Group has identified a new class of experimental malware, dubbed PROMPTFLUX, that can request code‑obfuscation from the Gemini AI model. One variant is programmed to have Gemini rewrite the entire malware source every hour, making each instance look different while preserving its malicious functionality.
Why self‑rewriting matters
Traditional security software relies heavily on signature detection—matching known patterns in malicious code. When malware constantly changes its appearance, those signatures become less effective, turning the threat into a moving target. However, Google notes that this does not automatically render the malware invisible; behavioral analysis and heuristic protections can still catch suspicious activity.
Current status and real‑world impact
Google says PROMPTFLUX was still under development when discovered and that no successful compromise of a victim’s device or network has been observed. The company disabled assets linked to the activity and continues to monitor the threat.
In a related development, Google reported an Android backdoor called PROMPTSPY that uses an AI module, GeminiAutomationAgent, to interpret on‑screen content and interact with the device. The backdoor can also place an invisible overlay over the uninstall button, thwarting removal attempts. Google confirmed that no apps containing PROMPTSPY were found on Google Play at the time of reporting, and known versions are detected by Google Play Protect.
Other AI‑assisted malware examples
The report also described PROMPTSTEAL, which queries the Qwen2.5‑Coder‑32B‑Instruct model via Hugging Face to generate Windows commands for data exfiltration. This variant can gather files from common folders and send them to attacker‑controlled servers.
Google’s broader findings indicate that attackers are moving from simple AI prompting toward more sophisticated, agentic AI workflows. In one case, a financially motivated group allegedly used an AI coding chatbot to plan, build, and execute a mass credential‑harvesting campaign against a cloud infrastructure in under six hours, compromising thousands of third‑party credentials.
What users can do
While AI‑enhanced malware remains experimental, users should keep security software up to date, enable real‑time monitoring, and rely on solutions that incorporate behavioral analysis and cloud‑based threat intelligence. On Android devices, ensure Google Play Protect is active, and be cautious about installing apps from unknown sources.
Cyber‑enabled crime continues to cost Americans billions each year. The FBI reported nearly $21 billion in losses for 2025, a 26 % increase from the prior year. Although AI malware is not yet the primary driver of those losses, its emergence underscores the need for robust, layered defenses.
Original reporting: Fox News (HLL/CB) — read the source article.