• Home
Wednesday, February 25, 2026
  • Login
Cosmos Flash
  • Home
  • Technology
    • AI & Machine Learning
    • Chat GPT
    • Cybersecurity & Privacy
    • Deepseek
    • Nvidia
  • Business & Finance
  • Defence
  • Android
  • Business & Finance
    • Gold
    • Reserve Bank Of India
  • Defence
    • Battle Tanks
    • Fighter Jets
    • Laser Weapons
  • Economy
  • Gadgets and Consumer Electronics
    • Laptops & PCs
    • Smartphones
  • Health & Medicine
  • Lifestyle
  • News
  • Science
    • Innovation & Research
  • Space & Astronomy
    • NASA
  • Telecom
  • Travel
No Result
View All Result
  • Home
  • Technology
    • AI & Machine Learning
    • Chat GPT
    • Cybersecurity & Privacy
    • Deepseek
    • Nvidia
  • Business & Finance
  • Defence
  • Android
  • Business & Finance
    • Gold
    • Reserve Bank Of India
  • Defence
    • Battle Tanks
    • Fighter Jets
    • Laser Weapons
  • Economy
  • Gadgets and Consumer Electronics
    • Laptops & PCs
    • Smartphones
  • Health & Medicine
  • Lifestyle
  • News
  • Science
    • Innovation & Research
  • Space & Astronomy
    • NASA
  • Telecom
  • Travel
No Result
View All Result
Cosmos Flash
No Result
View All Result

Google Unveils AI Malware That Rewrites Itself in Real-Time

Malware now thinks and evolves in real-time Google’s latest discovery reveals a new era of AI-powered cyber threats

November 6, 2025
in Technology, AI & Machine Learning
0
Google Unveils AI Malware That Rewrites Itself in Real-Time
0
VIEWS
Share on FacebookShare on Twitter

In a major new development that highlights the increasing complexity and multifaceted nature of the threat landscape, Google’s Threat Intelligence Group (GTIG) has discovered a new wave of malware that modifies its own code using artificial intelligence (AI) while running on an infected computer. This new class of malware represents a significant step forward in malicious software, capable of adapting on the fly and staying under the radar in real-time, serving as a whole new kind of threat to cyber defences.

The Rise of “Thinking” Malware

An experimental Visual Basic Script (VBScript) malware  , named PROMPTFLUX, was discovered by GTIG in early 2025. Unlike other threats, PROMPTFLUX has direct integration with Google’s Gemini AI language model through its API, enabling the malware to request new obfuscation and evasion code on demand, “just in time,” during an attack. This method, referred to as “just-in-time self-modification,” enables the malware to reach out to Gemini for new code snippets that give it the ability to evade antivirus detection techniques.

The ability to adapt is rooted in a “Thinking Robot” module of the malware. It sends obscure, machine-readable requests for Gemini, small VBScript functions designed to bypass security software. An even more state-of-the-art version of PROMPTFLUX attempts to make Gemini rewrite its own source code from scratch every hour, a programmatic reality analogous to Star Trek’s changeling or the Odo character from Deep Space Nine—a script that constantly metamorphoses and changes shape in response to static, signature-based defences.

While a few self-deletion functionalities in PROMPTFLUX were disabled or in the process of being implemented, the existence of such functionalities indicates that attackers are constructing malware that can evolve to be persistent and mutate on the spot within infected systems. The malware also creates persistence by dropping new obfuscated code variants into the Windows startup directory. It attempts to spread by copying itself to USB drives or network shares.

Broader AI-Enhanced Malware Landscape

PROMPTFLUX is only one example among a growing family of AI-powered malware identified by Google. Other families include:

  • FRUITSHELL: A PowerShell reverse shell that uses hard-coded prompts to get around AI-based security checks.
  • PROMPTLOCK: A cross-platform ransomware that uses AI to make harmful scripts while they are running.
  • PROMPTSTEAL (LAMEHUG): Russian state-sponsored hackers used a data miner to steal information by dynamically creating commands.
  • QUIETVAULT: A JavaScript credential thief that goes after GitHub and NPM tokens and uses AI to make it better.
  •  
  • This change indicates that attackers and defenders are engaged in an ongoing arms race that is constantly evolving. AI is no longer just a means to make things easier or automate phishing attacks; it is now a partner in cybercrime, allowing malware to evolve and grow while it is running.

State-Sponsored and Financially Motivated Threat Actors

Google’s study once again brings the focus to the table that both nation-state sponsored attackers from countries such as Iran, North Korea, China, etc, and financially motivated cybercriminals are resorting to using such AI-backed methods. Nation-state actors are weaponizing AI to create polymorphic malware that can bypass even the most sophisticated defences, while profit-driven attackers are testing wide-geography, geography-agnostic campaigns based on AI’s inherent flexibility.

Although it’s still in the testing phase, PROMPTFLUX’s actions, such as using filenames linked to social engineering lures, suggest that it has a financial goal. Google has taken steps to stop this malware from accessing Gemini’s API and has removed related assets to stop it from spreading.

Challenges for Cybersecurity

The advent of AI-based, self-evolving malware creates entirely new challenges in cybersecurity. Classic antivirus techniques utilize signatures as an indicator of compromise; however, this approach is ineffective for malware that continually changes its code and behaviour. The dynamic characteristics of these AI-enabled attacks have inspired security defenders to employ a class of “AI” for defence, allowing them to sense and adjust to evolving attack techniques.

The GTIG report from Google states that this new type of malware represents an early yet important step toward more self-sufficient and adaptable malicious software. Companies and security experts need to prepare for an increasing number of attacks that utilize generative AI, making them harder to detect, harder to stop, and easier to spread.


This discovery underscores the urgent need to rethink cybersecurity defense architectures amid the AI arms race, as malicious actors push the boundaries of what malware can do using AI—transforming malware from static code into ever-evolving threats.

Recent Posts

  • Paytm’s Game-Changing App Revamp: AI Smarts & Real Gold Rewards
  • Indian Telecom Giants Unite: Reserve 6 GHz Spectrum Exclusively for 5G
  • India Launches New Aadhaar App for 140 Crore Residents: Security & Convenience Redefined
  • PhysicsWallah IPO Raises ₹1,563 Crore: Edtech Giant’s Market Debut Shakes Up Industry
  • India’s Telecom Revolution: TRAI Declares Old Rules Obsolete & Launches Major Reform
Facebook Twitter

Archives

  • November 2025
  • October 2025
  • July 2025
  • June 2025

Categories

  • AI & Machine Learning
  • Air Pollution
  • Airtel
  • Amazon
  • AMD
  • Android
  • Apple
  • Automobile
  • Aviation
  • Banking
  • Battle Tanks
  • Broadcom
  • Business & Finance
  • Chat GPT
  • Chennai
  • China
  • Cognizant
  • Deepseek
  • Defence
  • Delhi
  • Drug War
  • Economy
  • Education
  • Environment & Energy
  • Fighter Jets
  • Gadgets and Consumer Electronics
  • Gold
  • Google
  • Health & Medicine
  • IBM
  • India
  • Indian Railways
  • Jio
  • Large Hadron Collider
  • Laser Weapons
  • Meta
  • Microsoft
  • NASA
  • National Capital Region
  • News
  • Nvidia
  • Open AI
  • PayPal
  • Pollution Control
  • RBI
  • Real Estate
  • Reliance
  • Reserve Bank Of India
  • Russia
  • Samsung
  • Science
  • Smartphones
  • Space & Astronomy
  • Technology
  • Technology Brands
  • Telecom
  • Top 10
  • Travel
  • TSMC
  • United States
  • USA
  • xiaomi
  • zoho

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • ABOUT US
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

Go to mobile version