Methods/Attack technique

Malware that queries an LLM at runtime

Malware that calls a hosted or locally run language model during execution to generate commands, scripts or new versions of itself, instead of carrying that logic hard-coded.

3 records3 attack1 findings (0 measured)First recorded 2025-08assistant-drafted

How it works

The implant carries prompts rather than fixed logic, sends them to a model API or a local open-weight model, and executes what comes back. Because the behavior is generated on the victim at run time, static signatures see less of it, and the same sample can act differently on each run.

Known limits

It depends on reaching a model service or carrying a local model, which creates network and resource signals, and hosted model access can be cut off by the provider. Several reported families are experimental or proofs of concept, and effectiveness against conventional malware has not been measured.

What we know

1 corroborated

Records over time

RangeLanes
3 of 3 records in view

Use the arrow keys to move between records, Home and End to jump to the first and last, and Enter to select one.

Agents find real bugsAgents in real operationsGated capability, incidents in the labAttackCapabilityDefensePolicyJan 25Jul 25Jan 26Jul 26
Full record · drag to choose a range
2026

Select a mark to read the record. Mark size shows editorial significance. Hollow marks are dated to the month. Era bands are editorial labels.

Records in view

3 records · newest first
Sep 2026
Sep 22, 2026
ThreatDown finds Carbonato, a Docker botnet that installs an AI agent to run operators’ tasks
AttackMalwareThreatDown

ThreatDown reports a botnet that compromises Docker hosts with unauthenticated APIs, installs the open-source Hermes Agent framework with a replaced persona file, and has the agent carry out tasks sent over Telegram, including collecting AI API keys and other credentials. ThreatDown recovered the operation's toolchain from an exposed registry, with images dating from October 2024 to August 2026, and describes the agent reading command output and deciding next steps in an operator-driven loop.

Nov 2025
Nov 5, 2025
Google reports malware that queries LLMs during execution, including APT28's PROMPTSTEAL
AttackMisuse reportGoogle Threat Intelligence Group, APT28

Google Threat Intelligence Group's AI Threat Tracker says adversaries moved beyond productivity uses in 2025 and began deploying malware that calls LLMs mid-execution, such as PROMPTFLUX, which asks Gemini to rewrite its own code, and PROMPTSTEAL, which queries a hosted open model for commands. GTIG attributes PROMPTSTEAL to Russia's APT28 in operations against Ukraine, and also reports actors posing as CTF players or researchers to get past safeguards and a maturing underground market for AI tools.

Aug 2025
Aug 26, 2025
ESET finds PromptLock, ransomware that writes its scripts with a local LLM, later tied to a research prototype
AttackMalwareESET

ESET Research reported PromptLock, ransomware samples uploaded to VirusTotal that use a locally run open-weight model to generate scripts for file discovery, exfiltration and encryption at runtime, and called it the first known AI-powered ransomware. In a September 3, 2025 update, ESET said the authors of an academic study had contacted it and that their research prototype closely resembles the samples, supporting ESET's view that PromptLock was a proof of concept rather than malware used in attacks.

All records