AI-Powered Malware Now Rewrites Its Own Code to Evade Detection
Google researchers document three malware families that use large language models during attacks, marking a fundamental shift in cyber threats.

Malicious software has entered a new phase: attackers are embedding AI capabilities directly into malware, enabling it to rewrite its own code, generate attack commands on the fly, and interpret what appears on infected devices.
Google's Threat Intelligence Group has documented three distinct malware families demonstrating these capabilities, according to research first reported by Fox News. The findings reveal how quickly experimental techniques are moving into operational attacks.
Why it matters
This represents a fundamental shift in the malware landscape. Traditional security approaches rely partly on recognizing known code patterns. When malware can continuously rewrite itself or generate new attack commands through AI models during an operation, it becomes a moving target. While modern antivirus tools use multiple detection layers beyond signature matching, the automation AI enables could allow less-skilled attackers to launch sophisticated campaigns at scale.
Three malware families show different AI approaches
The first family, PROMPTFLUX, was experimental VBScript malware discovered in June 2025. Its "Thinking Robot" component could contact Google's Gemini model and request new obfuscation techniques. One variant included instructions to rewrite the malware's entire source code every hour while preserving core functionality.
PROMPTSTEAL crossed into active operations. Google identified the Russian government-backed group APT28 deploying it against Ukrainian targets. Rather than rewriting itself, PROMPTSTEAL queries the Qwen2.5-Coder-32B-Instruct model through Hugging Face to generate Windows commands that gather system information and exfiltrate documents.
PROMPTSPY, an Android backdoor initially identified by ESET and detailed by Google in May 2026, demonstrates perhaps the most concerning capability. Its GeminiAutomationAgent module sends information about what appears on an infected Android screen to Gemini and uses the response to navigate the phone's interface. The malware can also place invisible overlays over uninstall buttons to prevent removal.
Attackers moving toward automation at scale
Google's September 2026 report documented attackers progressing from basic AI prompting toward agentic workflows. In one case, a suspected financially motivated attacker compromised cloud infrastructure and used an AI coding chatbot to plan, build, and execute a mass credential-harvesting campaign in under six hours. The system managed vulnerability scanning and troubleshooting autonomously, compromising thousands of credentials.
Google has not yet observed fully autonomous exploit pipelines deployed in the wild, but the trend shows AI taking on larger portions of attack operations with less human involvement.
Defense remains multilayered
Code rewriting does not render antivirus protection obsolete. Modern security tools employ behavioral analysis, heuristic detection, cloud-delivered threat intelligence, and machine learning alongside signature detection. Microsoft Defender Antivirus, for example, monitors real-time behavior that may reveal malicious intent even when code appearance changes.
The independent security institute AV-TEST registers more than 450,000 new malicious programs and potentially unwanted applications daily, underscoring why security tools already rely on multiple detection methods beyond recognizing known code patterns.
Protection strategies remain consistent: use antivirus software with behavioral monitoring, enable automatic updates, never execute commands from untrusted websites, download apps only from official sources, and maintain offline backups of critical data. Google Play Protect detects known PROMPTSPY variants and scans apps installed outside Google Play when enabled.
The research was detailed by Kurt "CyberGuy" Knutsson at Fox News, drawing from Google Threat Intelligence Group reports spanning June 2025 through September 2026.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call