{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/malware-queries-llms-in-operations/",
 "asOf": "2026-09-26",
 "id": "malware-queries-llms-in-operations",
 "claim": "Malware that queries a language model during execution to generate commands has been used in live operations, including by a state-backed group; self-rewriting variants have been seen only in testing.",
 "evidenceKind": "observed",
 "scope": "GTIG marks two of the five AI-enabled malware families in its 2025 overview as experimental, including the self-rewriting PROMPTFLUX, and other publicized cases, such as ESET’s PromptLock, were proofs of concept. The evidence does not show that runtime model use makes malware more effective or harder to detect in practice.",
 "topics": [
  "ai-malware",
  "threat-intelligence"
 ],
 "atlas": [],
 "evidence": [
  {
   "event": "gtig-ai-threat-tracker-llm-querying-malware-2025",
   "note": "GTIG attributes PROMPTSTEAL, which queries a hosted model for commands, to APT28 in operations against Ukraine."
  },
  {
   "event": "threatdown-carbonato-agent-botnet-2026",
   "note": "A criminal botnet installs an agent framework that interprets operators’ tasks and writes the commands it runs on compromised hosts; scripts, not the agent, spread it."
  }
 ],
 "relations": [
  {
   "type": "supersedes",
   "target": "early-attacker-llm-use-was-productivity",
   "note": "GTIG’s November 2025 update reports novel, model-using malware in operations, replacing its January 2025 finding of productivity-only use."
  }
 ],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2025-11-05",
   "why": "GTIG reports malware families that use LLMs during execution, some observed in operations.",
   "event": "gtig-ai-threat-tracker-llm-querying-malware-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2026-09-22",
   "why": "ThreatDown independently documents a botnet whose implant is an agent framework driven by a model.",
   "event": "threatdown-carbonato-agent-botnet-2026",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 365,
 "wouldChange": "Measurements comparing the detection and impact of LLM-querying malware with conventional malware, or further attributed operational cases.",
 "fideQuestions": [],
 "methods": [
  "runtime-llm-malware"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}