GTIG marks two of the five AI-enabled malware families in its 2025 overview as experimental, including the self-rewriting PROMPTFLUX, and other publicized cases, such as ESET’s PromptLock, were proofs of concept. The evidence does not show that runtime model use makes malware more effective or harder to detect in practice.
Corroborated: Supported by at least two independent sources.
Evidence
GTIG attributes PROMPTSTEAL, which queries a hosted model for commands, to APT28 in operations against Ukraine.
A criminal botnet installs an agent framework that interprets operators’ tasks and writes the commands it runs on compromised hosts; scripts, not the agent, spread it.
How it relates to other findings
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- This finding supersedes AI providers’ early reports found threat actors using LLMs mainly as productivity tools for research, scripting help and content, without novel attack capabilities.GTIG’s November 2025 update reports novel, model-using malware in operations, replacing its January 2025 finding of productivity-only use.
Key questions that rely on this finding
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.