Promptflux Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
19
occurrences
First Seen
November 5, 2025
Last Seen
May 11, 2026

Related Threat Clusters

  • Google Identifies AI-Driven Malware Families with Self-Modifying Capabilities

    Google's Threat Intelligence Group has discovered at least five new malware families that utilize artificial intelligence for self-modification during execution. This technique, referred to as 'just-in-time'…

    2 articles · Updated November 5, 2025
  • PromptFlux Malware Utilizes Gemini AI for Dynamic Code Mutation

    Google has identified a new malware named PromptFlux, which employs a VBScript dropper to dynamically rewrite and mutate its own code in real time using the Gemini API. This malware can adapt its code structure hourly,…

    2 articles · Updated November 5, 2025
  • Google GTIG Reports Shift in AI Misuse by Cyber Adversaries

    The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…

    3 articles · Updated November 5, 2025
  • PromptSpy: First Android Malware Utilizing Generative AI Discovered

    ESET researchers have identified PromptSpy, the first Android malware to incorporate generative AI, specifically Google’s Gemini, in its execution flow. This malware utilizes AI to manipulate the user interface and…

    39 articles · Updated February 19, 2026
  • Gemini AI Misused for Developing Self-Modifying Malware by Cybercriminals

    Nation-state actors and cybercrime groups are utilizing Gemini AI to create a 'Thinking Robot' malware module capable of rewriting its own code to evade detection. This development also includes an AI agent designed to…

    2 articles · Updated November 5, 2025
  • Debate on AI SOC Agents and Security Outcomes

    The discussion around AI Security Operations Centers (SOCs) is evolving, with Gartner's report highlighting the mainstream recognition of AI's potential in enhancing SOC functions. However, critiques emphasize that…

    52 articles · Updated November 16, 2025
  • State-Sponsored Hackers Exploit Google's Gemini AI for Cyberattacks

    State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…

    162 articles · Updated February 12, 2026
  • Gemini AI Misused for Advanced Malware Development by Cybercriminals

    Nation-state actors and cybercrime organizations are leveraging Gemini AI to create a 'Thinking Robot' malware module capable of self-modification to evade detection. This malware can also develop AI agents for tracking…

    2 articles · Updated November 5, 2025
  • PromptFlux Malware Uses Gemini AI for Real-Time Code Mutation

    Google has identified a new malware named PromptFlux, which employs a VBScript dropper that utilizes the Gemini API to dynamically rewrite and mutate its own code. This malware is designed to evade detection by altering…

    2 articles · Updated November 5, 2025

Recent Intelligence Reports

  • Ai Vulnerability Exploitation Initial Access — cloud.google.com · May 11, 2026
  • Google Threat Intelligence Group — www.anrdoezrs.net · May 11, 2026
  • GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access — Mandiant · May 11, 2026
  • This Android Malware Connects to Google Gemini for Tips on Hacking Targets — Uk.Pcmag · February 19, 2026
  • AI Malware Detected in the Wild as Threats Evolve — Thecyberexpress · November 7, 2025
  • Google warns of AI-powered malware targeting crypto users — Invezz · November 7, 2025
  • Google Threat Report Links AI-powered Malware to DPRK Crypto Theft — Decrypt.Co · November 7, 2025
  • Google finds first evidence of AI-enabled malware in the wild — Digit.Fyi · November 6, 2025

CVSS v3.1 Breakdown