Skip to content

Google finds first evidence of AI-enabled malware in the wild

Digit.Fyi November 6, 2025

A new Google threat report has warned that AI-powered malware is here, with hackers weaponising LLMs to unleash -gen malicious code near impossible to create with traditional tools.

In a new blog post , Google’s Threat Intelligence Group (GTIG) said it had observed a dramatic shift in the cyber landscape over the last year, with adversaries no longer restricting their AI use to productivity gains like creating lures or attack research, but deploying AI-enabled malware in active operations.

For the first time, Google said it had identified new malware families in the wild that are using AI to generate malicious scripts on the fly, disguise their own code to avoid detection, and build attack functions in real time, rather than relying on pre-written payloads.

“This marks a new operational phase of AI abuse, involving tools that dynamically alter behaviour mid-execution,” said the report.

“While still nascent, this represents a significant step toward more autonomous and adaptive malware.”

Among the new malware strains identified by Google is PromptSteal, a Python-based data miner linked to the Russian Fancy Bear group, that uses Hugging Face’s API to query a powerful LLM and spit out one-line Windows commands designed to harvest system info and documents from specific folders.

Even more worrying is PromptFlux, a dropper that uses ‘dynamic obfuscation techniques’ to hide behind a decoy installer while quietly rewriting itself using Google’s Gemini API.

Luckily, Google’s researchers estimate that PromptFlux is not yet being used in active campaigns, and can’t currently compromise a victim network or device. The tech firm said it had taken action to disable the assets associated with this strain, hopefully stamping it out.

While Google claims that these novel malware families mark a pivotal shift toward self-directed malware, it’s not the world’s first glimpse of AI-powered cyber-attacks.

Earlier this year, researchers at ESET made headlines with PromptLock, a proof-of-concept ransomware using a freely available genAI model to execute attacks, including the generation of malicious scripts served directly to infected devices.

Although that particular strain is safely locked up in the lab, Google’s findings show that hackers have moved fast to weaponise the concept.

Extracted Entities

APT Groups (1)

Attack Types (2)

Countries (1)

Platforms (1)

Ransomware Groups (1)