Rogue Agent Watch › Records › promptflux-gemini-selfmod
PROMPTFLUX — experimental self-modifying malware abusing the Gemini API
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- Low — Minimal direct harm; primarily notable as a precedent or signal.
Summary
In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group described PROMPTFLUX, an experimental VBScript dropper that queries the Google Gemini API at runtime (via a hard-coded key) to request obfuscation code and rewrite its own source for antivirus evasion — a "metamorphic" self-modification technique — before persisting to the Startup folder. Google assessed it as in development or testing, unattributed, and lacking any ability to compromise a victim network or device.
Impact as stated
No successful compromise: Google assessed PROMPTFLUX as experimental. Notable as an early example of malware that outsources its own obfuscation/evasion to a hosted LLM at runtime.
Facts as stated by sources
- Actor
- Unknown (Unknown)
- Category
- Infrastructure abuse / supply chain
- Models named
- gemini-1.5-flash-latest
- Model families
- Gemini (Google)
- Agentic autonomy level
- Supervised-autonomous
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Resource development, Execution, Persistence
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0016.002, AML.T0102
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
Sources (3)
- GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
Google Threat Intelligence Group · Vendor report · · archived copy - Attackers abuse Gemini AI to develop 'Thinking Robot' malware
The Register · News · · archived copy - Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
The Hacker News · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "promptflux-gemini-selfmod". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/promptflux-gemini-selfmod.json — CC BY-SA 4.0.