logo

Google warns of new AI-powered malware families deployed in the wild

ID: f4e0062a-408c-5dad-ac4e-14466c70660f

STIX ID: report--f4e0062a-408c-5dad-ac4e-14466c70660f

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-05

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Google Threat Intelligence Group details a surge in AI-powered malicious tooling and abuse of the Gemini LLM: experimental and operational malware families (PromptFlux, PromptSteal, FruitShell, QuietVault, PromptLock) leverage LLMs for dynamic code generation, evasion, credential theft, and C2; multiple nation-state and criminal groups have used Gemini for vulnerability research, phishing, malware development, and data exfiltration; underground marketplaces are increasingly offering AI-enabled attack services, and Google has taken steps to disable abused accounts and strengthen model safeguards.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.