Google finds AI malware that rewrites code to evade detection
Google's Threat Intelligence Group identified experimental malware called PROMPTFLUX, which uses Gemini to rewrite its own code hourly to avoid signature-based detection. Although PROMPTFLUX was still in development and had not successfully compromised a device, it represents an early example of "just-in-time" AI integration in malware. Google also reported PROMPTSTEAL, used by the Russian…
Key points
- PROMPTFLUX malware uses Gemini to rewrite its code hourly to evade signature-based security detection.
- APT28 used PROMPTSTEAL in live attacks, querying Qwen2.5-Coder-32B-Instruct to generate Windows commands.
- Google reports attackers are shifting to agentic AI workflows, with one campaign harvesting credentials in six hours.
A third threat, PROMPTSPY, was an Android backdoor that used an AI module to understand on-screen content and navigate the interface, even placing invisible overlays to prevent uninstallation. Google stated that no apps containing PROMPTSPY were found on Google Play and that Play Protect detects known versions. In a broader report from September 8, 2026, Google noted attackers are moving toward agentic AI workflows, with one example involving a mass credential-harvesting campaign executed in under six hours using an AI coding chatbot. While fully autonomous exploit pipelines have not yet been observed in the wild, the trend indicates AI is taking on larger roles in cyberattacks.
The volume of new malware remains high, with AV-TEST registering over 450,000 new malicious programs daily. The FBI reported nearly $21 billion in cyber-enabled crime losses in the US during 2025, a 26% increase from the previous year. Experts advise users to maintain real-time behavioral detection, keep software updated, and avoid pasting commands from untrusted websites.
AI malware can rewrite itself to evade detection
foxnews.com · 22 September 2026
Loading the full article…
This text was published by foxnews.com and written by Kurt Knutsson, CyberGuy Report. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Policy & Regulation
All →- US virtual border wall, including AI towers, fails to prevent deaths, investigation finds · 1 src
- Anthropic CEO Dario Amodei urges global AI development pause over rogue agent risks · 33 src
- DeepSeek and Moonshot to brief UN security council on AI risks · 2 src
- OpenAI fires contractors for using AI to train its models, report says · 1 src
- IAB announces AAMP 3.0 with OpenProposal spec for AI media buying · 1 src
Comments
via GitHub Discussions