Bitget App
Trade smarter
Cybercriminals Are Now Using AI to Create Shape-Shifting Malware, Google Warns

Cybercriminals Are Now Using AI to Create Shape-Shifting Malware, Google Warns

DeFi PlanetDeFi Planet2025/11/07 14:57
By:DeFi Planet

Quick Breakdown

  • Cybercriminals and state-backed groups are using large language models to create malware that can rewrite and adapt itself during attacks.
  • These AI-powered malware strains are already being used to target high-value crypto assets through technical exploits and advanced phishing.
  • Google has shut down linked accounts and strengthened safeguards, but warns that AI-driven cyber threats are rapidly evolving.

 

Google’s Threat Intelligence Group (GTIG) has reported a new wave of cyberattacks driven by artificial intelligence, revealing that both criminal networks and state-backed hacking teams are now deploying malware that can rewrite and adapt itself on the fly.

Cybercriminals Are Now Using AI to Create Shape-Shifting Malware, Google Warns image 0 Source: Google

The report outlines five separate malware families that interact directly with LLMs such as Google’s Gemini and Alibaba’s Qwen2.5-Coder, requesting fresh code, new command sequences, or obfuscation techniques while they run. This method allows the malware to change its appearance or behavior fast enough to evade detection tools that rely on pattern recognition and known code signatures.

Inside the AI-powered malware families

GTIG examined two of these malware strains closely. The first, known as PROMPTFLUX, continuously calls Gemini’s API to regenerate its VBScript code approximately every hour. The second strain, PROMPTSTEAL, has been connected to the Russian state-linked group APT28. Instead of operating off pre-written instructions, it sends prompts to a Qwen model hosted on Hugging Face to produce Windows command sequences tailored to the victim’s system. 

GTIG refers to this as a “just-in-time code creation” model. By generating code only when needed, attackers gain flexibility and stealth, enhancing their ability to respond to system defenses, user behavior, or new obstacles in real time.

AI-Driven attacks targeting crypto holders

The report underscores that these attacks are not hypothetical; they are already being deployed, with cryptocurrency users among the primary targets. The North Korean group UNC1069, also known as Masan, has been using AI tools to locate vulnerable crypto wallets, develop more convincing phishing websites, and compose highly targeted scam messages designed to bypass suspicion.

The group broadened their infiltration of blockchain firms beyond the United States, now targeting companies in the United Kingdom and Europe, according to a different GTIG report .

Google responds with new safeguards

In response, Google has moved to suspend accounts tied to malicious LLM activity and has tightened restrictions around its APIs. Additional monitoring and prompt-filtering systems have also been introduced to make it harder for attackers to misuse AI generative tools.

However, GTIG cautions that as AI capabilities expand and open-source models remain widely accessible, the threat of adaptive, self-rewriting malware is likely to continue growing.

 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

You may also like

Bitcoin News Update: Short-Term Holders Increase Holdings While Long-Term Holders Realize Gains—$100K Becomes Key Level

- Bitcoin fell below $100,000 as Coinbase premium hit a seven-month low, reflecting weak U.S. demand and ETF outflows. - On-chain data shows short-term holders (STHs) accumulating Bitcoin while long-term holders (LTHs) moved 363,000 BTC to STHs, signaling mixed market dynamics. - Analysts highlight a "mid-bull phase" with STHs absorbing selling pressure, and a $113,000 support level critical for potential rallies to $160,000–$200,000 by late 2025. - The Fear and Greed Index entered "Extreme Fear," and exch

Bitget-RWA2025/11/07 19:12
Bitcoin News Update: Short-Term Holders Increase Holdings While Long-Term Holders Realize Gains—$100K Becomes Key Level

Bitcoin Update: Large Holders Depart and Economic Instability Push Bitcoin Under $100K

- Bitcoin fell below $100,000 as OG whales BitcoinOG and Owen Gunden moved $1.8B BTC to exchanges, signaling bearish bets. - $260M in long positions liquidated amid SOPR spikes, while Trump's crypto policies and China's $20.7B BTC holdings added macro risks. - Bit Digital staked 86% of ETH holdings for 2.93% yield, while Coinbase's negative premium highlighted waning U.S. buyer demand. - Analysts warn consolidation phases often follow whale profit-taking, with geopolitical tensions and derivatives volatili

Bitget-RWA2025/11/07 19:12
Bitcoin Update: Large Holders Depart and Economic Instability Push Bitcoin Under $100K

Aster DEX's Latest Protocol Enhancement and What It Means for DeFi Liquidity Providers

- Aster DEX upgraded its protocol on Nov 5, 2025, enabling ASTER token holders to use their assets as 80% margin collateral for leveraged trading and receive 5% fee discounts. - Binance's CZ triggered a 30% ASTER price surge and $2B trading volume spike via a $2M token purchase three days prior, highlighting market speculation and utility convergence. - The platform introduced a "Trade & Earn" model allowing yield-generating assets like asBNB and USDF to be used as trading margin, enhancing capital efficie

Bitget-RWA2025/11/07 19:08
Aster DEX's Latest Protocol Enhancement and What It Means for DeFi Liquidity Providers

XRP Update: Digitap's Practical Applications Put XRP's Delayed Ambitions to the Test

- Digitap ($TAP) raised $1.4M in November 2025, outpacing rivals like Bitcoin Hyper and Pepenode with an 80% early investor discount. - The project combines crypto and fiat banking via a live app, Visa cards, and deflationary tokenomics, positioning it as XRP's real-world competitor. - $TAP's fixed 2B token supply and transaction-burning model create scarcity, with analysts projecting 50x-70x price growth by late 2026. - Digitap's 124% APR staking rewards and privacy-focused features like offshore-shielded

Bitget-RWA2025/11/07 18:54
XRP Update: Digitap's Practical Applications Put XRP's Delayed Ambitions to the Test