AI-Powered Malware Rewrites Itself to Evade Detection
Google's Threat Intelligence Group discovered an experimental malware called PROMPTFLUX that uses AI to rewrite its own code. The malware can contact Gemini, a large language model, and request new obfuscation techniques to evade detection.
The 'Thinking Robot' component of PROMPTFLUX allows it to generate new versions of itself every hour while preserving the necessary functionality. This makes it difficult for security software to recognize the malware, as it is constantly changing its appearance.
However, Google notes that this does not make the malware invisible to current security tools. Modern antivirus protection uses real-time monitoring, behavioral analysis, and machine learning to identify new threats, even if they do not match a known malware signature.
PROMPTSTEAL is another AI-powered malware discovered by Google, which queries a large language model to gather information about a computer and copy documents from folders. The malware then sends the collected data back to the attacker's infrastructure.
The use of AI in malware is becoming more prevalent, with Google observing attackers experimenting with automated reconnaissance and frameworks designed to manage harvested credentials. While AI can make certain aspects of cyberattacks easier, threat actors have not yet deployed fully autonomous exploit pipelines against targets in the wild.