Google’s latest malware findings point to a sharp new problem: malicious code that can change its own look and behavior to slip past defenses. Experimental tools such as PROMPTFLUX, live attack activity tied to PROMPTSTEAL, and Android threats like PROMPTSPY show how AI is moving from a buzzword to an active part of cybercrime. The bigger picture is simple and unsettling, attackers want automation, flexibility, and speed, while defenders have to keep up in real time.
Google’s Threat Intelligence Group spotted PROMPTFLUX as a work-in-progress malware sample that could ask Gemini to help rewrite its code. One version was designed to refresh itself every hour, which is exactly the kind of trick that makes detection harder for security tools that lean on known patterns. If the code keeps morphing, the threat becomes a moving target instead of a fixed one.
That does not mean antivirus suddenly becomes useless. Modern security software is not just a static list of bad files, and many products watch behavior, system changes, and suspicious actions as they happen. Changing the code may help malware dodge one layer of defense, but it does not erase all the other signals that can give it away.
Google says PROMPTFLUX was still in development when it was found, and the company moved to shut down related assets. That matters, because it shows the line between research and real-world threat can get thin fast. Once this kind of AI help is built into malware, the same idea can be used for more aggressive attacks if the code reaches the wild.
PROMPTSTEAL took that step further. Google identified the Russian government-backed group APT28 using it in attacks against targets in Ukraine, making it the first time the company observed malware querying a large language model during live operations. Instead of rewriting itself, the malware asked an AI coding model for Windows commands it could run to gather information and pull files from common folders like Documents, Downloads, and Desktop.
That shift is a big deal because the AI is no longer just a helper in the background. It becomes part of the attack flow itself, feeding commands into the operation while the malware is already inside a system. Less manual effort, more automation, and a lot more room for attackers to move quickly.
On mobile devices, PROMPTSPY shows another ugly possibility. Google says the Android backdoor included a module called GeminiAutomationAgent, which could send screen information to Gemini and use the response to help navigate a victim’s phone. In plain English, the malware could study what was on the device and use AI to decide what to do next.
It also tried to make removal harder. When someone attempted to uninstall it, the malware could place an invisible overlay over the uninstall button so the taps appeared to fail. Google says it took action against the actor behind the malware, and known versions are detected by Play Protect, but the message is clear: Android threats are getting smarter about both control and persistence.
Google’s broader reporting shows attackers are also chasing more automation in cloud and enterprise environments. In one case, a suspected financially motivated attacker used AI tools and instructions to build and launch a credential-harvesting campaign in under six hours, with the system helping troubleshoot problems along the way. That kind of speed changes the game, because it compresses the time defenders have to spot the intrusion and respond.
The scale of the malware problem makes this even more serious. Security researchers already deal with a flood of new malicious samples every day, and criminals are clearly interested in anything that helps them churn out more attacks with less effort. Add AI into that mix, and the pressure on security teams only gets heavier.
The best protection still starts with the basics, but the basics have to be strong. Security software should be kept on, updates should install automatically, and warnings from browsers or operating systems should be taken seriously instead of clicked through on autopilot. A good password manager, multifactor authentication, and careful app habits all help close the door before malware gets a foothold.
One warning stands out more than the rest: never paste a command into your computer just because a website tells you to. That trick has become a favorite move for attackers using fake CAPTCHA pages or bogus errors to lure people into opening dangerous system tools. The new AI-powered malware headlines are flashy, but the old-school scams are still busy doing damage right next to them.
