Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
07.11.2025
5870

Google discovers PROMPTFLUX malware using Gemini AI to rewrite and hide its code for smarter evasion.
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
Google just dropped a bombshell: they've uncovered PROMPTFLUX malware that's weaponizing Gemini AI to completely rewrite its own code EVERY HOUR. This isn't your grandpa's malware — it's using generative AI to constantly morph and evade detection like some cyber chameleon on steroids.
The malware uses sophisticated code obfuscation techniques powered by Google's own Gemini AI model. Think about the irony — Google's AI being used against its own security infrastructure. The malware authors are basically turning Google's tech against them in some next-level cyber warfare move.
This PROMPTFLUX threat represents a massive escalation in the AI-powered cybercrime arms race. We're talking about malware that can automatically regenerate its signature, change its behavioral patterns, and adapt to security measures in near real-time. This makes traditional signature-based detection completely useless against it.
Google's Threat Intelligence team discovered this while investigating sophisticated phishing campaigns targeting enterprise networks. The malware was hiding in seemingly legitimate software updates and using the hourly code rewrites to maintain persistence while avoiding antivirus scans.
The implications are terrifying for cybersecurity pros. We're entering an era where malware can essentially 'think' and adapt using the same AI tools that security teams use for defense. This PROMPTFLUX discovery should be a wake-up call for every security team still relying on traditional detection methods.

Published by Ravie Lakshmanan on November 5, 2025, this discovery highlights the urgent need for AI-powered defense systems that can match the evolving sophistication of AI-powered attacks. The cat-and-mouse game just got a whole lot more complicated.
- • PROMPTFLUX malware uses Gemini AI for hourly code rewriting
- • Represents major escalation in AI-powered cybercrime
- • Makes traditional signature-based detection obsolete
- • Discovered by Google's Threat Intelligence team
- • Targets enterprise networks through phishing campaigns
- • Uses sophisticated code obfuscation techniques
- • Highlights need for AI-powered defense systems
#malware#Artificial Intelligence#obfuscation#phishing
Got a topic? Write to ATLA WIRE on Telegram:t.me/atla_community

