PROMPTFLUX is an experimental Windows VBScript malware family best characterized as a dropper that integrates a large language model into its execution flow to achieve polymorphic self-modification. It uses Google Gemini during runtime to rewrite or obfuscate its own VBScript source code, producing regenerated variants intended to evade static signature-based antivirus and EDR detection. This behavior has been described as an early example of just-in-time AI-enabled malware, where the model is used as an active component of the malware rather than only as an offline development aid.
PROMPTFLUX has been associated with live calls to the Gemini API, including reports of hardcoded API access in samples. Its core behavior is repeated source-code regeneration between executions or during operation, with the rewritten script written back to disk as a new variant. High-confidence reporting consistently describes it as a self-morphing dropper focused on obfuscation and defense evasion. Some reporting also describes persistence through Windows startup-folder placement of regenerated copies.
The malware targets Windows systems and has been publicly discussed alongside other AI-enabled malware families such as HONESTCUE, PROMPTSTEAL, QUIETVAULT, PROMPTLOCK, and PROMPTSPY. It has been presented as one of the earliest documented malware families to operationalize runtime LLM access for evasive code transformation. Reporting characterizes it as nascent, experimental, and under active development rather than a mature, widely deployed malware platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors are using large language models to write polymorphic loaders... Public reporting now names specific actor clusters in the wild... APT27... used Gemini to accelerate development of fleet management tooling... APT45... sending thousands of repetitive prompts that recursively analyze CVEs and validate proof-of-concept exploits
PromptFlux VBScript dropper that queries Gemini to generate obfuscated VBScript variants for AV evasion.
...two newly disclosed malware families that leverage AI for evasive techniques such as polymorphism...
PROMPTFLUX makes live calls to the Gemini API to dynamically modify itself, HONESTCUE queries Gemini at runtime to request specific VBScript obfuscation routines just-in-time so the bytes on disk at minute zero differ from the bytes at minute thirty.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code, bypassing static signature-based detection.
„…PROMPTFLUX… ein sogenannter ‘Dropper’, der seine maliziöse Aktivität mit Hilfe eines Fake-Installationsprogramms verbirgt.“ / „Die Malware tarnt sich als Programm zur Bildgenerierung…“
PromptFlux is a POC malware sample that abuses Gemini-like services for command-and-control operations. | The malware exploits Gemini API access to receive instructions or exfiltrate data, often using hard-coded keys or unauthorized requests.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family described as regenerating its own source code on each execution through an LLM, enabling polymorphism without traditional packers or crypters.
VBScript dropper that uses an LLM during execution to generate obfuscated variants intended to evade antivirus detection.
An autonomous malware framework described as using LLMs to rewrite its own malicious functions on the fly, generating polymorphic variants to evade EDR detection.
AI-enabled dropper that uses Google Gemini via a hardcoded API key to rewrite its own VBScript source between runs, enabling polymorphism and evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.