{"id":130910,"date":"2025-11-09T19:33:09","date_gmt":"2025-11-09T19:33:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/130910\/"},"modified":"2025-11-09T19:33:09","modified_gmt":"2025-11-09T19:33:09","slug":"malware-is-now-using-ai-to-rewrite-its-own-code-to-avoid-detection","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/130910\/","title":{"rendered":"Malware Is Now Using AI to Rewrite Its Own Code to Avoid Detection"},"content":{"rendered":"<p class=\"pw-incontent-excluded article-paragraph skip\">Researchers at Google\u2019s Threat Intelligence Group (GTIG) have discovered that hackers are creating malware that can harness the power of large language models (LLMs) to rewrite itself on the fly.<\/p>\n<p class=\"article-paragraph skip\">An experimental malware family dubbed PROMPTFLUX, identified by GTIG in a <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/threat-actor-usage-of-ai-tools\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">recent blog post<\/a>, can rewrite its own code to avoid detection.<\/p>\n<p class=\"article-paragraph skip\">It\u2019s an escalation that could make future malware far more difficult to detect, further highlighting <a href=\"https:\/\/futurism.com\/artificial-intelligence\/serious-new-hack-openai-ai-browser\" rel=\"nofollow noopener\" target=\"_blank\">growing cybersecurity concerns<\/a> brought on by the advent and widespread adoption of generative AI.<\/p>\n<p class=\"article-paragraph skip\">Tools like PROMPTFLUX \u201cdynamically generate malicious scripts, obfuscate their own code to evade detection, and leverage AI models to create malicious functions on demand, rather than hard-coding them into the malware,\u201d GTIG wrote.<\/p>\n<p class=\"article-paragraph skip\">According to the tech giant, this new \u201cjust-in-time\u201d approach \u201crepresents a significant step toward more autonomous and adaptive malware.\u201d<\/p>\n<p class=\"article-paragraph skip\">PROMPTFLUX is a Trojan horse malware that interacts with Google\u2019s Gemini AI model\u2019s application programming interface (API) to learn how to modify itself to avoid detection on the fly.<\/p>\n<p class=\"article-paragraph skip\">\u201cFurther examination of PROMPTFLUX samples suggests this code family is currently in a development or testing phase since some incomplete features are commented out and a mechanism exists to limit the malware\u2019s Gemini API calls,\u201d the group wrote.<\/p>\n<p class=\"article-paragraph skip\">Fortunately, the exploit has yet to be observed infecting machines in the wild, as the \u201ccurrent state of this malware does not demonstrate an ability to compromise a victim network or device,\u201d Google noted. \u201cWe have taken action to disable the assets associated with this activity.\u201d<\/p>\n<p class=\"article-paragraph skip\">Nonetheless, GTIG noted that malware like PROMPTFLUX appears to be \u201cassociated with financially motivated actors.\u201d The team warned of a maturing \u201cunderground marketplace for illicit AI tools,\u201d which could lower the \u201cbarrier to entry for less sophisticated actors.\u201d<\/p>\n<p class=\"article-paragraph skip\">The threat of adversaries leveraging AI tools is very real. According to Google, \u201cState-sponsored actors from North Korea, Iran, and the People\u2019s Republic of China\u201d are already tinkering with the AI to enhance their operations.<\/p>\n<p class=\"article-paragraph skip\">In response to the threat, GTIG introduced a new conceptual framework aimed at securing AI systems.<\/p>\n<p class=\"article-paragraph skip\">While generative AI can be used to create almost impossible-to-detect malware, it can be used for good as well. For instance, Google recently introduced an AI agent, <a href=\"https:\/\/blog.google\/technology\/safety-security\/cybersecurity-updates-summer-2025\/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">dubbed Big Sleep<\/a>, which is designed to use AI to identify security vulnerabilities in software.<\/p>\n<p class=\"article-paragraph skip\">In other words, it\u2019s AI being pitted against AI in a cybersecurity war that\u2019s evolving rapidly.<\/p>\n<p class=\"article-paragraph skip\">More on AI and cybersecurity: <a href=\"https:\/\/futurism.com\/artificial-intelligence\/serious-new-hack-openai-ai-browser\" rel=\"nofollow noopener\" target=\"_blank\">Serious New Hack Discovered Against OpenAI\u2019s New AI Browser<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Researchers at Google\u2019s Threat Intelligence Group (GTIG) have discovered that hackers are creating malware that can harness the&hellip;\n","protected":false},"author":2,"featured_media":130911,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[220,218,219,61,60,80],"class_list":{"0":"post-130910","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-ie","12":"tag-ireland","13":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/130910","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=130910"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/130910\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/130911"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=130910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=130910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=130910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}