Google Threat Intelligence Group's AI Threat Tracker says adversaries moved beyond productivity uses in 2025 and began deploying malware that calls LLMs mid-execution, such as PROMPTFLUX, which asks Gemini to rewrite its own code, and PROMPTSTEAL, which queries a hosted open model for commands. GTIG attributes PROMPTSTEAL to Russia's APT28 in operations against Ukraine, and also reports actors posing as CTF players or researchers to get past safeguards and a maturing underground market for AI tools.
APT28
Russian military intelligence (GRU Unit 26165) cyber actor. Overlaps with Microsoft's Forest Blizzard (formerly STRONTIUM); Google tracks it as FROZENLAKE.
2 records2 attack
Nov 5, 2025
Google reports malware that queries LLMs during execution, including APT28's PROMPTSTEAL
Feb 14, 2024
Microsoft and OpenAI report state-backed hackers using LLMs as a productivity tool
Microsoft Threat Intelligence, publishing jointly with OpenAI, describes five state-affiliated actors from Russia, North Korea, Iran and China using LLMs for tasks such as research, scripting help and drafting phishing content. Microsoft says it and OpenAI had not seen novel or unique AI-enabled attack techniques, and that assets and accounts associated with the actors were disrupted.