Google’s security team has uncovered a new breed of malware that could signal a dangerous shift in cyber threats.

Dubbed PROMPTFLUX, the AI-powered malware can rewrite its own code on the fly, making it nearly impossible for traditional antivirus software to detect.

Unlike conventional malware that follows fixed scripts, PROMPTFLUX leverages AI to “learn” and adapt during an attack.

It interacts with Google’s Gemini AI to request on-demand obfuscation and generate new attack methods, effectively morphing its digital fingerprint in real time.

According to Google’s Threat Intelligence Group (GTIG), the malware is still in its experimental stage.

Current samples are incomplete and no infections have been reported in the wild.

Google has already shut down the associated accounts and assets.

Google Australia Sydney Office

Cybersecurity experts warn that PROMPTFLUX represents one of the first real-world examples of adaptive, AI-driven malware.

Traditional signature-based detection relies on recognising a virus’s static code, but a malware that evolves every few seconds could render these systems obsolete.

The discovery also highlights a growing underground market for AI tools that could allow low-skilled hackers to deploy sophisticated attacks.

State-backed groups in North Korea, Iran and China are reportedly exploring AI to enhance cyber operations, from intrusion to influence campaigns.

In response, Google is developing “counter-AI” systems, including programs like Big Sleep, designed to detect and patch vulnerabilities before AI-powered threats can exploit them.

Experts advise organisations to focus on behaviour-based detection, monitor model-API usage and secure developer and automation credentials.