Google Threat Intelligence Group's AI Threat Tracker says adversaries moved beyond productivity uses in 2025 and began deploying malware that calls LLMs mid-execution, such as PROMPTFLUX, which asks Gemini to rewrite its own code, and PROMPTSTEAL, which queries a hosted open model for commands. GTIG attributes PROMPTSTEAL to Russia's APT28 in operations against Ukraine, and also reports actors posing as CTF players or researchers to get past safeguards and a maturing underground market for AI tools.
It is Google's evidence that malware using models at runtime had reached a state operation, after CERT-UA's earlier report of the same malware, and it replaced Google's own productivity-only picture.
Key facts
As stated in the sources, with where to find them.
- GTIG calls APT28’s use of PROMPTSTEAL, which CERT-UA reported as LAMEHUG, its first observation of malware querying an LLM in live operations.Threat Actors Developing Novel AI Capabilities
- Of five AI-enabled malware families in GTIG’s overview, three are marked observed in operations and two experimental.Table 1
- The report updates GTIG’s January 2025 analysis, which had found no novel capabilities.Executive summary
Findings that cite this record
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.