Google Warns of AI Malware That Thinks and Rewrites Its Own Code

Key Takeaways

  • Google warns of new AI malware that can think, adapt, and rewrite its own code autonomously.
  • Hackers are using social engineering to trick AI models like Gemini into writing malicious code.
  • A booming black market for AI hacking tools is making advanced cyberattacks accessible to novices.

Google’s Threat Intelligence Group has revealed a dangerous new era in cybersecurity where AI-powered malware can think and rewrite its own code during an attack, making it highly evasive.

Self-Evolving Malware: PROMPTFLUX and PROMPTSTEAL

Google identified specific malware strains like PROMPTFLUX and PROMPTSTEAL that use Large Language Models (LLMs). These threats generate new malicious scripts every time they execute.

PROMPTFLUX, written in VBScript, sends commands to the Gemini API to request help writing complex, encrypted code designed to bypass antivirus software.

Conversely, PROMPTSTEAL, reportedly used by the Russian APT28 group against Ukraine, disguises itself as an image generation tool. It uses the Qwen model to create commands for stealing local data without any pre-written code.

Photo: cloud.google.com

Hackers Are Now Tricking AI Systems

The report highlights that hackers are using sophisticated social engineering against AI. They use innocent-seeming pretexts, like pretending to be a Capture-the-Flag contestant to get Gemini to suggest vulnerabilities, or claiming to be a student needing coding help for a final project.

This demonstrates a significant shift, as attackers now actively deceive AI systems, not just humans.

The Rapidly Growing Black Market for AI Hacking Tools

In 2025, the black market for AI-powered hacking tools has exploded. Services like WormGPT, FraudGPT, and LoopGPT are being sold, offering capabilities from writing phishing emails to creating malware and exploiting system vulnerabilities.

Photo: cloud.google.com

This accessibility allows even novice hackers to create highly complex malware. Simultaneously, state-sponsored groups are leveraging these AIs for attack planning, intelligence gathering, and developing sophisticated phishing campaigns and command-and-control servers.

Google’s Counter-Offensive

In response, Google has closed accounts and projects linked to malicious actors and is continuously refining its Gemini models to be smarter and more resistant to misuse.

Google is also collaborating with DeepMind to develop AI tools like Big Sleep and CodeMender, which will automatically detect and patch vulnerabilities. The ultimate goal is to create advanced, safe AI, ensuring responsible use in an age where AI is both a powerful weapon and a crucial shield.

Source: Google

Photo: cloud.google.com

Latest

Former Meta contractor Sama to lay off more than 1,000 workers in Kenya

Former Meta contractor Sama to lay off more than 1,000 workers in Kenya

AI is a gold mine for spammers and scammers, but Google is using it as a tool to fight back

AI is a gold mine for spammers and scammers, but Google is using it as a tool to fight back

OpenAI policy chief slams AI doomers, says we need to have more responsible conversations

OpenAI’s David Lehane urges responsible discussions around AI, highlighting risks of extreme narratives and stressing the need for balanced public understandi

AI startup Cluely hiring engineer, says it will offer free home, food and even a partner in 1 year

San Francisco-based AI startup Cluely offers a unique job package including free housing, food, and a guaranteed partner after one year.

WhatsApp may soon introduce business chat filtering to reduce spam

WhatsApp reportedly working on a new feature to reduce spam and clutter. The purported feature will help users organise business messages and keep personal chat

Topics

Schools in Kerala, MP and other states change timings, declare holidays amid heatwave

States take action to safeguard students from extreme heat

Kendriya Vidyalaya students score 90%+ in CBSE, share success mantra

With CBSE declaring the Class 10 results, students across India are celebrating their scores and planning their next academic steps. At PM SHRI Kendriya Vidyala

Aadi Abadi factor: How delimitation, women voters shape Tamil Nadu poll narrative

Women voters emerge as pivotal in Tamil Nadu's heated election scene

Markets open flat as geopolitical tensions ease, but caution remains

The BSE Sensex was trading at 78,030.99, up 42.31 points or 0.05% at around 9:43 am. The Nifty 50, however, slipped marginally by 6.85 points or 0.03% to 24,189

Kerala SSLC Results in May, plus two on May 25, confirms education minister

Kerala SSLC and Plus Two Result 2026 dates have been officially announced, giving students clarity on when to expect their scores. The state has also rolled out

Who is Girija Ji? PM Modi meets veteran educationist after 30 years, praises her work

Prime Minister Narendra Modi’s Nagercoil visit blended politics and personal warmth as he reunited with veteran educationist Gomatam Veeraraghavan Girija afte

Lebanon ceasefire: Who said what? Bibi vows troops will stay; Trump hails talks ‘very exciting’ – How Iran reacts?

Iranian Parliament speaker Ghalibaf asserts that Lebanon must be included in any peace agreement between Iran and the U.S., emphasizing its importance for regio

‘Targeting of commercial shipping unacceptable,’ India calls restoration of safe navigation in Strait of Hormuz at UN

India's Ambassador Harish P raised concerns at the UN over threats to commercial shipping in the Strait of Hormuz, urging for safe navigation and calling for de
spot_img

Related Articles

Popular Categories

spot_imgspot_img