Back to Home
Technology

‘PromptFlux’ malware rewrites its code with AI every hour

Google cybersecurity researchers discovered experimental malware that uses the Gemini model to rewrite its code periodically and evade detection. The researchers identified 70 variants in less than four hours, while technical reports say modern security tools can still track its behaviour and digital fingerprint.

•3 min

Listen to this article

An automatically generated audio version.

0:00
0:00
An illustration shows three anonymous hooded figures using laptops against a background of blue programming symbols and open padlocks.

Google’s Cybersecurity Intelligence Group discovered experimental malware that uses the Gemini artificial intelligence tool to rewrite its code every hour, in an attempt to make detection more difficult for antivirus and anti-malware applications.

‘PromptFlux’ changes its code through Gemini

The security group named the malware ‘PromptFlux’. It appeared in several variants that differed in how they used artificial intelligence. One variant asks Gemini to rewrite all the code it contains every hour while retaining the parts necessary to carry out its task, while another uses the model to alter specific sections of the code rather than rewrite it in full.

This mechanism gives the malware a greater ability to evade security measures that compare files and programmes with known malicious patterns identified previously. As the code changes continuously, detection becomes more like tracking a moving target that does not retain the same programming form for long.

A technical report by Cybersecurity News said researchers identified 70 different variants of ‘PromptFlux’, designed with the help of artificial intelligence in less than four hours. This malware is not the only example of this approach: other groups of malware that alter their code in the same way to reduce the chances of detection have emerged recently.

The technique used in attacks attributed to APT28

In a use linked to real-world attacks, a Fox News report said the hacking group APT28, which is alleged to have links to the Russian government, used malware based on this approach in attacks targeting multiple entities in Ukraine. In that case, the group did not rely on Gemini, but used Alibaba’s Qwen 2.5 model.

However, the emergence of malware capable of improving itself automatically during an attack does not mean that cybersecurity applications have become ineffective. The Cybersecurity News report said that rewriting the code makes detection more difficult, but does not completely prevent security tools from identifying the malware.

Malware retains something resembling a fingerprint that distinguishes it, and artificial intelligence tools cannot rewrite its code in a way that completely conceals this fingerprint. The malware can therefore still be detected and tracked, even if large parts of its code structure change.

Security tools track behaviour and digital fingerprints

Security applications such as Windows Defender, which is pre-installed on Windows systems, use artificial intelligence and machine-learning technologies to scan for malware and continuously assess threats. Antivirus programmes also do not rely solely on recognising a programme’s name or code; they monitor suspicious activity within the system and alert the user to it.

When a security application detects unusual behaviour, it can automatically classify it as being linked to malware, even if it cannot identify the malware itself.

The spread of this type of threat highlights the importance of using up-to-date antivirus and anti-malware applications, particularly tools that connect directly to the internet to obtain the latest security data.