PROMPTFLUX is an experimental AI-enabled malware family, most consistently described as a VBScript dropper that uses Google Gemini during execution to rewrite or obfuscate its own source code for evasion. Multiple sources characterize it as one of the earliest documented examples of malware using an LLM as an active runtime component rather than only as a development aid. The malware makes live calls to the Gemini API, including Gemini 1.5 Flash, and some reporting states it used a hardcoded API key. Its core behavior is just-in-time self-modification: it prompts the model to generate modified or obfuscated VBScript variants, writes regenerated versions back to disk, and periodically changes its code to reduce the effectiveness of static signatures and traditional EDR detections. Some reporting also states it attempted lateral movement or limited propagation via removable media and network shares, and that regenerated copies were stored in Windows startup locations for persistence. Detection-focused content additionally notes staging in temporary directories, anomalous outbound Gemini API traffic from unusual processes, and possible script execution outside normal workflows. PROMPTFLUX has been cited by Google Threat Intelligence Group and other reporting as AI-embedded malware under active development, with researchers observing repeated sample uploads to VirusTotal consistent with detection-evasion testing. It is discussed alongside other AI-enabled malware such as HONESTCUE and PROMPTSTEAL, but the provided content does not attribute PROMPTFLUX to a specific threat actor with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors are using large language models to write polymorphic loaders... Public reporting now names specific actor clusters in the wild... APT27... used Gemini to accelerate development of fleet management tooling... APT45... sending thousands of repetitive prompts that recursively analyze CVEs and validate proof-of-concept exploits
PROMPTFLUX requested obfuscation techniques from Google’s Gemini AI, demonstrate how adversaries are moving past traditional, static malware.
...two newly disclosed malware families that leverage AI for evasive techniques such as polymorphism...
PROMPTFLUX makes live calls to the Gemini API to dynamically modify itself, HONESTCUE queries Gemini at runtime to request specific VBScript obfuscation routines just-in-time so the bytes on disk at minute zero differ from the bytes at minute thirty.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code, bypassing static signature-based detection.
„…PROMPTFLUX… ein sogenannter ‘Dropper’, der seine maliziöse Aktivität mit Hilfe eines Fake-Installationsprogramms verbirgt.“ / „Die Malware tarnt sich als Programm zur Bildgenerierung…“
PromptFlux is a POC malware sample that abuses Gemini-like services for command-and-control operations. | The malware exploits Gemini API access to receive instructions or exfiltrate data, often using hard-coded keys or unauthorized requests.
Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An autonomous malware framework described as using LLMs to rewrite its own malicious functions on the fly, generating polymorphic variants to evade EDR detection.
AI-enabled dropper that uses Google Gemini via a hardcoded API key to rewrite its own VBScript source between runs, enabling polymorphism and evasion.
A loader that dynamically modifies itself at runtime via Gemini API calls to enable rapid polymorphism and evasion.
A malware family described as dynamically modifying itself at runtime via live Gemini API calls, enabling rapid polymorphism and evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.