PROMPTFLUX is an experimental VBScript dropper that incorporates a hosted large language model into its runtime operation. It uses the Gemini API to periodically request rewritten and obfuscated versions of its own VBScript source, then regenerates its code to reduce the effectiveness of static hashes and signature-based detection. Researchers observed rapid production of numerous distinct variants during testing, indicating an early implementation of AI-assisted polymorphic evasion. Google Threat Intelligence Group identified PROMPTFLUX as under active development and characterized its behavior as attempted self-modification and detection evasion. No high-confidence attribution to a specific threat actor, confirmed mass campaign, victim sector, or delivery vector has been established. PROMPTFLUX targets Windows environments through its use of VBScript.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors are using large language models to write polymorphic loaders... Public reporting now names specific actor clusters in the wild... APT27... used Gemini to accelerate development of fleet management tooling... APT45... sending thousands of repetitive prompts that recursively analyze CVEs and validate proof-of-concept exploits
“AI now helps attackers generate malware and phishing tools faster and continuously mutate their code. Instead of a fixed signature a security tool can recognize, each version looks a little different and can evade detection.”
...two newly disclosed malware families that leverage AI for evasive techniques such as polymorphism...
PROMPTFLUX makes live calls to the Gemini API to dynamically modify itself, HONESTCUE queries Gemini at runtime to request specific VBScript obfuscation routines just-in-time so the bytes on disk at minute zero differ from the bytes at minute thirty.
“A malicious dropper can request a newly obscured version of itself at regular intervals” and “the sample reportedly queried the Gemini API about once an hour and regenerated obfuscated code, with researchers seeing more than 70 variants in under four hours.”
„…PROMPTFLUX… ein sogenannter ‘Dropper’, der seine maliziöse Aktivität mit Hilfe eines Fake-Installationsprogramms verbirgt.“ / „Die Malware tarnt sich als Programm zur Bildgenerierung…“
PromptFlux is a POC malware sample that abuses Gemini-like services for command-and-control operations. | The malware exploits Gemini API access to receive instructions or exfiltrate data, often using hard-coded keys or unauthorized requests.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AI-assisted malware reportedly capable of querying an AI model during an attack to rewrite its code and evade detection.
Experimental AI-powered dropper that repeatedly queries an LLM API to regenerate obfuscated versions of its code, creating rapidly changing variants intended to undermine signature- and hash-based detection.
Experimental AI-assisted dropper that repeatedly queries a language-model API to regenerate obfuscated code, producing rapidly changing variants that undermine static hash and signature-based detection.
Malware family described as regenerating its own source code on each execution through an LLM, enabling polymorphism without traditional packers or crypters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.