{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-llm-querying-malware-2025/",
 "asOf": "2026-09-26",
 "id": "gtig-ai-threat-tracker-llm-querying-malware-2025",
 "date": "2025-11-05",
 "datePrecision": "day",
 "title": "Google reports malware that queries LLMs during execution, including APT28's PROMPTSTEAL",
 "lane": "attack",
 "kind": "misuse-report",
 "summary": "Google Threat Intelligence Group's AI Threat Tracker says adversaries moved beyond productivity uses in 2025 and began deploying malware that calls LLMs mid-execution, such as PROMPTFLUX, which asks Gemini to rewrite its own code, and PROMPTSTEAL, which queries a hosted open model for commands. GTIG attributes PROMPTSTEAL to Russia's APT28 in operations against Ukraine, and also reports actors posing as CTF players or researchers to get past safeguards and a maturing underground market for AI tools.",
 "whyItMatters": "It is Google's evidence that malware using models at runtime had reached a state operation, after CERT-UA's earlier report of the same malware, and it replaced Google's own productivity-only picture.",
 "actors": [
  "google-threat-intelligence-group",
  "apt28"
 ],
 "topics": [
  "ai-malware",
  "threat-intelligence",
  "jailbreaks-and-safeguards"
 ],
 "atlas": [],
 "artifacts": [
  "gemini"
 ],
 "sources": [
  {
   "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools",
   "publisher": "Google Threat Intelligence Group",
   "title": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools",
   "date": "2025-11-05",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "GTIG calls APT28’s use of PROMPTSTEAL, which CERT-UA reported as LAMEHUG, its first observation of malware querying an LLM in live operations.",
   "locator": "Threat Actors Developing Novel AI Capabilities"
  },
  {
   "fact": "Of five AI-enabled malware families in GTIG’s overview, three are marked observed in operations and two experimental.",
   "locator": "Table 1"
  },
  {
   "fact": "The report updates GTIG’s January 2025 analysis, which had found no novel capabilities.",
   "locator": "Executive summary"
  }
 ],
 "significance": 5,
 "fideQuestions": [],
 "methods": [
  "jailbreaking",
  "runtime-llm-malware"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}