Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware
ID: 2bbbe0eb-f547-5191-aeda-951e44f0394c
STIX ID: report--2bbbe0eb-f547-5191-aeda-951e44f0394c
Date Published: 2025-09-19
Date Updated: 2026-07-27
Author: Alex Delamotte, Vitaly Kamluk & Gabriel Bernadett-Shapiro
This research briefing presents SentinelLABS’ investigation into LLM-enabled malware, detailing how adversaries embed or leverage large language models to generate code or commands at runtime, with case studies including PromptLock (PoC ransomware), MalTerminal (early LLM-enabled sample), and LameHug/PROMPTSTEAL (attributed to APT28). The report explains hunting techniques (API key and prompt detection), defensive implications (runtime-generated malicious logic, mixed network traffic, and brittle dependencies like API keys), and includes IOCs such as file hashes and examples of malicious prompts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
