Skip to main content
Mallory
MalwareUsed by 3 actors

HONESTCUE

HONESTCUE is an AI-enabled downloader and launcher framework that leverages Google Gemini’s API to generate or modify second-stage functionality on demand. Reporting states that it sends prompts to Gemini and receives C# source code in response, then uses the legitimate .NET CSharpCodeProvider framework to compile and execute that payload directly in memory, enabling a fileless second stage that downloads and executes additional malware. Multiple sources also describe HONESTCUE as requesting just-in-time VBScript obfuscation routines from Gemini at runtime so that the bytes on disk change over time, supporting polymorphic behavior and undermining signature-based detection and static analysis. It has been described as sending benign-looking prompts to generate working code that is compiled and executed in memory, apparently to help bypass safety filters. Google Threat Intelligence Group reported tracking HONESTCUE samples in September 2025 and described the malware as outsourcing functionality generation through Gemini. GTIG stated it had not associated HONESTCUE with an existing threat cluster and suspected it was being developed by a single actor or small group based on iterative sample changes and a single VirusTotal submitter. High-confidence behaviors directly mentioned in the content include Gemini API use, on-demand malicious C# code generation, in-memory compilation and execution via CSharpCodeProvider, stage-two downloader/launcher functionality, and runtime VBScript obfuscation for evasion.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
China

The report identified attempts to coerce disclosure of internal reasoning, AI-assisted reconnaissance by DPRK, PRC, Iranian, and Russian actors, and AI-integrated malware such as HONESTCUE leveraging Gemini’s API for second-stage payload generation.

via checkpoint research blogresearch.checkpoint.com
DPRK

The report identified attempts to coerce disclosure of internal reasoning, AI-assisted reconnaissance by DPRK, PRC, Iranian, and Russian actors, and AI-integrated malware such as HONESTCUE leveraging Gemini’s API for second-stage payload generation.

via checkpoint research blogresearch.checkpoint.com
russian_actors

The report identified attempts to coerce disclosure of internal reasoning, AI-assisted reconnaissance by DPRK, PRC, Iranian, and Russian actors, and AI-integrated malware such as HONESTCUE leveraging Gemini’s API for second-stage payload generation.

via checkpoint research blogresearch.checkpoint.com
MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

T1587Develop CapabilitiesEvidence1

"detected a malware called HONESTCUE that leverages Gemini's API to outsource functionality generation for the next-stage" ... "receives C# source code as the response."

T1587.001MalwareEvidence1

threat actors are using large language models to write polymorphic loaders... Public reporting now names specific actor clusters in the wild... APT27... used Gemini to accelerate development of fleet management tooling... APT45... sending thousands of repetitive prompts that recursively analyze CVEs and validate proof-of-concept exploits

Execution

1 technique
T1059.005Visual BasicEvidence3
TacticExecution

HONESTCUE queries Gemini at runtime to request specific VBScript obfuscation routines just-in-time

Stealth

6 techniques
T1027Obfuscated Files or InformationEvidence6
TacticStealth

an attacker can ask a fine-tuned open-weights model to regenerate a loader with different control-flow structure, different string encoding, and different sandbox-evasion tells... PROMPTFLUX makes live calls to the Gemini API to dynamically modify itself, HONESTCUE queries Gemini at runtime to request specific VBScript obfuscation routines

T1027.002Software PackingEvidence1
TacticStealth

...two newly disclosed malware families that leverage AI for evasive techniques such as polymorphism...

T1027.007Dynamic API ResolutionEvidence1
TacticStealth

PROMPTFLUX makes live calls to the Gemini API to dynamically modify itself, HONESTCUE queries Gemini at runtime to request specific VBScript obfuscation routines just-in-time so the bytes on disk at minute zero differ from the bytes at minute thirty.

T1027.014Polymorphic CodeEvidence1
TacticStealth

Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code, bypassing static signature-based detection.

T1497Virtualization/Sandbox EvasionEvidence1

...the development of evasive malware. The report highlighted two previously discovered and two newly disclosed malware families that leverage AI for evasive techniques...

T1620Reflective Code LoadingEvidence4
TacticStealth

“...receives source code for a second-stage downloader, compiles it in memory with .NET tools, and executes it without writing files to disk. This fileless approach helps evade detection.”

Discovery

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

...the development of evasive malware. The report highlighted two previously discovered and two newly disclosed malware families that leverage AI for evasive techniques...

T1071Application Layer ProtocolEvidence1

"HONESTCUE ... sends a prompt via Google Gemini's API and receives C# source code as the response"

T1071.001Web ProtocolsEvidence1

Promptflux : A self-morphing dropper that calls the Gemini API to periodically rewrite its own source code

T1102Web ServiceEvidence1

“...malware called HONESTCUE that uses the Gemini API to generate malicious C# code on demand.”

T1105Ingress Tool TransferEvidence1

“Attackers also host payloads on platforms like Discord CDN.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.