Security researchers have identified a new wave of threats where adversaries embed Large Language Model (LLM) capabilities directly into malware, enabling malicious code to be generated at runtime and evading traditional detection methods. SentinelLABS highlighted real-world cases such as PromptLock ransomware and APT28’s LameHug/PROMPTSTEAL campaigns, noting that while these threats are adaptive, they often hardcode artifacts like API keys and prompts, which can be leveraged for detection. Novel hunting strategies, including YARA rules for API key structures and prompt detection, have uncovered thousands of LLM-enabled malware samples, including previously unknown threats like MalTerminal.
In parallel, security vendors are leveraging LLMs defensively, as seen in NodeZero’s Advanced Data Pilfering (ADP) feature, which uses LLMs to identify hidden credentials and assess the business risk of compromised data. By applying semantic analysis to unstructured data, defenders can better understand what attackers might target and how to prioritize response. These developments underscore both the offensive and defensive potential of LLMs in cybersecurity, with attackers and defenders racing to exploit the technology’s unique capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Horizon3.ai announced NodeZero Advanced Data Pilfering, a capability intended to let organizations view their exposed data from an attacker's perspective. No additional dated milestones or incident details were provided in the reference synopsis.
At LABScon 2025, SentinelLabs researchers Alex Delamotte and Gabriel Bernadett-Shapiro presented findings on real-world LLM-enabled malware, including PromptLock ransomware and APT28's LameHug/PROMPTSTEAL campaigns. The presentation highlighted how attackers embed LLM capabilities into malware and how defenders can detect these threats by hunting for hardcoded prompts and API keys.
During a year-long VirusTotal retrohunt, SentinelLabs developed YARA-based hunting methods focused on embedded API keys and prompt structures, discovering more than 7,000 samples and over 6,000 unique API keys. The effort also uncovered "MalTerminal," which the researchers describe as potentially the earliest known LLM-enabled malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.