Cronkite

Bulletin of September 22, 2026

6 minNews

Google Uncovers Experimental AI Malware That Rewrites Its Own Code

Google's Threat Intelligence Group has identified PROMPTFLUX, an experimental malware that uses Gemini to rewrite its own code and evade detection. The discovery highlights a broader trend of AI being integrated into live cyberattacks, including Russian-backed operations in Ukraine and an Android backdoor called PROMPTSPY.

Google's Threat Intelligence Group has uncovered an experimental form of malware that can ask an artificial intelligence model to rewrite its own code, a technique designed to make the malicious software harder for security tools to recognize. The malware, dubbed PROMPTFLUX, was still under development when researchers found it and had not been observed successfully compromising a victim's device or network. Google said it disabled the assets connected to the activity.

PROMPTFLUX was a VBScript-based project discovered in June 2025. Its most notable component, called the «Thinking Robot,» could contact Google's Gemini model and request new obfuscation techniques to make its code harder for security software to identify. Google later found multiple variations of the malware, including one that instructed Gemini to rewrite the entire source code every hour while preserving the parts needed for it to keep running.

The approach creates a moving target for defenders. Security software often relies on signature detection, which recognizes the digital fingerprints of known malicious code. If that code keeps changing, one layer of detection becomes less effective. However, modern antivirus tools do much more than compare files against a list of known threats. Microsoft Defender Antivirus, for example, uses real-time monitoring, behavioral analysis, heuristic protection, cloud-delivered protection and machine learning to identify new threats that may not match a known signature. Changing the code does not automatically make malware invisible, and a security tool may still notice suspicious behavior once the program starts doing something dangerous.

Google described PROMPTFLUX as an early example of «just-in-time» AI being built directly into malware. Instead of relying entirely on functions written ahead of time, the malware can ask an AI model for help while it runs. That distinction matters because it points to a future in which malicious software adapts during an attack rather than following a fixed script.

The concern extends beyond experimental projects. Google has since documented AI being used by malware during live attacks. It identified the Russian government-backed group APT28 using a tool called PROMPTSTEAL against targets in Ukraine. Google said this was its first observation of malware querying a large language model while deployed in live operations.

PROMPTSTEAL takes a different approach from PROMPTFLUX. Rather than asking AI to rewrite itself, it queries the Qwen2.5-Coder-32B-Instruct model through Hugging Face. The model generates Windows commands that the malware can execute. Those commands can gather information about a computer and copy documents from folders including Documents, Downloads and Desktop. The malware then sends the collected information back to infrastructure controlled by the attacker. In this case, the AI model becomes part of what the malware does after it starts running.

Google also detailed an Android backdoor called PROMPTSPY, which was initially identified by ESET and reported in May 2026. The malware contains an AI-powered module called GeminiAutomationAgent. It can send information about what appears on an infected Android device to Gemini and use the response to help navigate the phone's interface. In other words, the malware can use AI to understand part of what is happening on the screen and determine how to interact with it.

Google found that PROMPTSPY could also make itself harder to remove. When a victim tried to uninstall it, the malware could place an invisible overlay over the uninstall button so taps would appear to do nothing. Google said it took action against the actor behind the malware and that no apps containing PROMPTSPY were found on Google Play at the time of its May report. Known versions are detected by Google Play Protect, which is enabled by default on Android devices with Google Play Services.

The discoveries illustrate a broader shift. Malware can begin reacting to the device it finds instead of relying only on instructions written before the attack starts. PROMPTFLUX was experimental and did not achieve a successful compromise, but PROMPTSTEAL crossed an important line by querying a large language model during live operations. PROMPTSPY shows how AI could help malware understand and respond to a victim's device in real time.

For defenders, the challenge is not that every layer of modern antivirus suddenly stops working. It is that AI-assisted malware can make some forms of detection harder while forcing security tools to rely more on behavior and less on static signatures. Google's findings suggest that the integration of AI into malware is no longer purely theoretical, and that the tools used to protect devices will need to keep pace with software that can change while it runs.

5Views

Hailey Griffin

Author

Staff Reporter

Hailey Griffin covers public affairs, politics, business, culture and daily news for Cronkite. The role focuses on verification, context, and clear explanations for readers.

Tail slate

Reporter
Hailey Griffin
Filed
Runs
6 min
Source
fox - Most Popular
Block
News

Next in the News block

  1. ——:—— Sep 22 Mississippi Grand Jury Clears Friends in Nolan Wells Drowning Death 5 min
  2. ——:—— Sep 22 Tropical Storm Polo Intensifies Into Hurricane, Threatens Southwest Flooding 3 min
  3. ——:—— Sep 21 Leavitt Recounts Trump's Push to Return to WHCA Dinner After Shooting 3 min
  4. ——:—— Sep 21 CNN, MS NOW and Politico Sue Trump Administration Over White House Access 4 min