Rogue Agent Watch › Records › promptflux-gemini-selfmod

PROMPTFLUX — experimental self-modifying malware abusing the Gemini API

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
Low — Minimal direct harm; primarily notable as a precedent or signal.

Summary

In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group described PROMPTFLUX, an experimental VBScript dropper that queries the Google Gemini API at runtime (via a hard-coded key) to request obfuscation code and rewrite its own source for antivirus evasion — a "metamorphic" self-modification technique — before persisting to the Startup folder. Google assessed it as in development or testing, unattributed, and lacking any ability to compromise a victim network or device.

Impact as stated

No successful compromise: Google assessed PROMPTFLUX as experimental. Notable as an early example of malware that outsources its own obfuscation/evasion to a hosted LLM at runtime.

Facts as stated by sources

Actor
Unknown (Unknown)
Category
Infrastructure abuse / supply chain
Models named
gemini-1.5-flash-latest
Model families
Gemini (Google)
Agentic autonomy level
Supervised-autonomous
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Resource development, Execution, Persistence
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0016.002, AML.T0102

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (3)

  1. GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
    Google Threat Intelligence Group · Vendor report · · archived copy
  2. Attackers abuse Gemini AI to develop 'Thinking Robot' malware
    The Register · News · · archived copy
  3. Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
    The Hacker News · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptflux-gemini-selfmod". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptflux-gemini-selfmod.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction