Google's Threat Intelligence Group (GTIG) has identified a significant evolution in cybercriminal and nation-state tactics, with adversaries now leveraging Gemini AI to develop advanced malware and data processing agents. Notably, groups such as APT42 have experimented with Gemini to create a 'Thinking Robot' malware module capable of rewriting its own code during execution to evade detection, as well as AI agents that process and analyze sensitive personal data for surveillance and intelligence gathering. These developments mark a shift from previous uses of AI for productivity, such as phishing and translation, to direct integration of AI into malware operations.
The experimental PromptFlux malware dropper exemplifies this trend, utilizing Gemini to dynamically generate obfuscated VBScript variants and periodically update its code to bypass antivirus defenses. PromptFlux attempts persistence via Startup folder entries and spreads through removable drives and network shares, while its 'Thinking Robot' module queries Gemini for new evasion techniques. Although PromptFlux is still in early development and not yet capable of causing significant harm, Google has proactively disabled its access to the Gemini API. Other AI-powered malware, such as FruitShell, have also been observed, indicating a broader move toward AI-driven, self-modifying threats in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
GTIG reported increasing interest on English- and Russian-language underground forums in AI-enabled tools and services for malware creation, phishing, reconnaissance, deepfakes, and exploitation support. Google assessed that these offerings are lowering the barrier to entry and will likely increase the scale and complexity of attacks.
Google said it disabled accounts associated with the observed abuse, blocked PromptFlux's Gemini API access, deleted related assets, and strengthened Gemini protections based on the bypass techniques it observed. Some reporting also said Google shared intelligence with law enforcement.
GTIG said the PromptSteal malware family, also referred to as LameHug in some reporting, was deployed by Russia-linked APT28 in Ukraine. The malware queried an LLM in real time to generate Windows system-harvesting commands for data collection.
Google disclosed PROMPTFLUX, an experimental VBScript dropper that uses the Gemini API and a 'Thinking Robot' component to request obfuscation and evasion code and rewrite itself over time. GTIG assessed the malware as still under development/testing, with persistence and propagation features but no confirmed built-in initial compromise mechanism.
GTIG reported multiple malware families embedding or querying LLMs during execution, including PromptFlux, PromptSteal/LameHug, FruitShell, QuietVault, and PromptLock. Google described this as a shift from proof-of-concept use of AI to malware that can dynamically generate commands, obfuscate code, steal data, or support reverse shells in real-world activity.
Google Threat Intelligence Group documented that state-linked and criminal actors from countries including China, Iran, North Korea, and Russia were using Gemini and other LLMs for phishing, reconnaissance, vulnerability research, malware development, obfuscation, and data analysis. The activity also included attempts to bypass model safeguards through social-engineering pretexts such as posing as students or CTF participants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethecyberthrone.in
Open sourcesecurityonline.info
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.