Findings/malware-queries-llms-in-operations

Malware that queries a language model during execution to generate commands has been used in live operations, including by a state-backed group; self-rewriting variants have been seen only in testing.

Corroboratedobserved2 evidence records from 2 independent sourcesassistant-drafted
Scope: what this does not show

GTIG marks two of the five AI-enabled malware families in its 2025 overview as experimental, including the self-rewriting PROMPTFLUX, and other publicized cases, such as ESET’s PromptLock, were proofs of concept. The evidence does not show that runtime model use makes malware more effective or harder to detect in practice.

Corroborated: Supported by at least two independent sources.

Evidence

How it relates to other findings

supportsqualifiescontestssupersedes
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic

Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.

Key questions that rely on this finding

Status history

  1. 2025-11-05ReportedGTIG reports malware families that use LLMs during execution, some observed in operations. · record
  2. 2026-09-22CorroboratedThreatDown independently documents a botnet whose implant is an agent framework driven by a model. · record