Cybercriminals Are Now Using AI to Create Shape-Shifting Malware, Google Warns
Quick Breakdown
- Cybercriminals and state-backed groups are using large language models to create malware that can rewrite and adapt itself during attacks.
- These AI-powered malware strains are already being used to target high-value crypto assets through technical exploits and advanced phishing.
- Google has shut down linked accounts and strengthened safeguards, but warns that AI-driven cyber threats are rapidly evolving.
Google’s Threat Intelligence Group (GTIG) has reported a new wave of cyberattacks driven by artificial intelligence, revealing that both criminal networks and state-backed hacking teams are now deploying malware that can rewrite and adapt itself on the fly.
Source:
Google
The report outlines five separate malware families that interact directly with LLMs such as Google’s Gemini and Alibaba’s Qwen2.5-Coder, requesting fresh code, new command sequences, or obfuscation techniques while they run. This method allows the malware to change its appearance or behavior fast enough to evade detection tools that rely on pattern recognition and known code signatures.
Inside the AI-powered malware families
GTIG examined two of these malware strains closely. The first, known as PROMPTFLUX, continuously calls Gemini’s API to regenerate its VBScript code approximately every hour. The second strain, PROMPTSTEAL, has been connected to the Russian state-linked group APT28. Instead of operating off pre-written instructions, it sends prompts to a Qwen model hosted on Hugging Face to produce Windows command sequences tailored to the victim’s system.
GTIG refers to this as a “just-in-time code creation” model. By generating code only when needed, attackers gain flexibility and stealth, enhancing their ability to respond to system defenses, user behavior, or new obstacles in real time.
AI-Driven attacks targeting crypto holders
The report underscores that these attacks are not hypothetical; they are already being deployed, with cryptocurrency users among the primary targets. The North Korean group UNC1069, also known as Masan, has been using AI tools to locate vulnerable crypto wallets, develop more convincing phishing websites, and compose highly targeted scam messages designed to bypass suspicion.
The group broadened their infiltration of blockchain firms beyond the United States, now targeting companies in the United Kingdom and Europe, according to a different GTIG report .
Google responds with new safeguards
In response, Google has moved to suspend accounts tied to malicious LLM activity and has tightened restrictions around its APIs. Additional monitoring and prompt-filtering systems have also been introduced to make it harder for attackers to misuse AI generative tools.
However, GTIG cautions that as AI capabilities expand and open-source models remain widely accessible, the threat of adaptive, self-rewriting malware is likely to continue growing.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Aster DEX's Latest Protocol Enhancement and What It Means for DeFi Liquidity Providers
- Aster DEX upgraded its protocol on Nov 5, 2025, enabling ASTER token holders to use their assets as 80% margin collateral for leveraged trading and receive 5% fee discounts. - Binance's CZ triggered a 30% ASTER price surge and $2B trading volume spike via a $2M token purchase three days prior, highlighting market speculation and utility convergence. - The platform introduced a "Trade & Earn" model allowing yield-generating assets like asBNB and USDF to be used as trading margin, enhancing capital efficie

XRP Update: Digitap's Practical Applications Put XRP's Delayed Ambitions to the Test
- Digitap ($TAP) raised $1.4M in November 2025, outpacing rivals like Bitcoin Hyper and Pepenode with an 80% early investor discount. - The project combines crypto and fiat banking via a live app, Visa cards, and deflationary tokenomics, positioning it as XRP's real-world competitor. - $TAP's fixed 2B token supply and transaction-burning model create scarcity, with analysts projecting 50x-70x price growth by late 2026. - Digitap's 124% APR staking rewards and privacy-focused features like offshore-shielded

Vitalik Buterin Unveils a Fresh ZK Perspective and What It Means for the Crypto Industry
- Vitalik Buterin's GKR protocol revolutionizes ZK scalability, slashing verification costs by 10-15x and enabling ZKsync's 15,000 TPS with near-zero fees. - ZKsync's 150% token surge and institutional adoption by Citibank highlight ZK's market potential, while Starknet and Immutable expand use cases in DeFi and gaming. - Despite progress, Ethereum's modexp bottleneck and regulatory scrutiny of privacy coins like Zcash underscore technical and compliance challenges for ZK's long-term viability.

Vitalik Buterin Backs ZKsync: Accelerating Ethereum Layer 2 Expansion and Driving DeFi Growth
- Vitalik Buterin endorsed ZKsync's Atlas upgrade, praising its transformative potential for Ethereum's scalability and DeFi. - The upgrade's unified liquidity framework enables real-time settlements and near-zero fees, attracting 30+ institutions like Citibank. - ZKsync's TVL lags behind competitors, but ZK token's 30x trading volume surge reflects investor confidence in its tokenomics overhaul. - Institutional adoption and Buterin's support highlight ZKsync's role in bridging DeFi and traditional finance

