GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors
GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' (TL-2026-1508), also tracked as GTIG AI Threat Tracker, is a high-severity malware campaign, first published 2026-07-19. It is attributed to APT28 (Russia) with medium confidence, affects Google Gemini (generative AI platform), maps to 34 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1508
- Threat ID
- TL-2026-1508
- Also known as
- GTIG AI Threat Tracker, LAMEHUG (CERT-UA name for PROMPTSTEAL)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-19
- Last reviewed
- 2026-07-19
- Attribution
- APT28
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, cryptocurrency, finance, technology, defense, criticalinfrastructure
- Target regions
- ukraine, Global, North America, Middle East, Europe
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'
Malware and tooling: BIGMACHO, CHROMEPUSH, DEEPBREATH, FRUITSHELL, LAMEHUG - S9035, PROMPTFLUX, PromptLock, QUIETVAULT, SILENCELIFT, OSSTUN
Google Threat Intelligence Group (GTIG) documents the first confirmed operational deployment of 'just-in-time' AI-enabled malware — families that query LLM APIs (Gemini, Hugging Face) at runtime to dynamically generate, obfuscate, or rewrite malicious code. State-sponsored actors APT28 (Russia), TEMP.Zagros/MuddyWater and APT42 (Iran), UNC1069 and UNC4899 (North Korea), and APT41 (China) misused Google Gemini for reconnaissance, phishing, C2 development, exploit research, and code obfuscation; Google disabled all associated accounts/projects.
How GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' works
In its November 5, 2025 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) reports a new operational phase of adversarial AI misuse: malware that dynamically alters its own behavior mid-execution by querying large language models at runtime, rather than merely using AI as a productivity aid during development. PROMPTFLUX is a self-modifying VBScript dropper containing a 'Thinking Robot' module that sends hardcoded POST requests to the Gemini API (gemini-1.5-flash-latest) asking an LLM acting as 'an expert VBScript obfuscator' to rewrite its own source code for antivirus evasion; a 'Thinging' variant regenerates its entire source hourly, logs responses to %TEMP% hinking_robot_log.txt, and a commented-out AttemptToUpdateSelf function signals unfinished intent toward full metamorphic self-propagation. It persists via the Startup folder and spreads to removable drives and mapped network shares; it remains experimental/R&D with no confirmed wild compromise capability, and uses decoy filenames such as crypted_ScreenRec_webinstall suggesting a financially motivated, unattributed actor. PROMPTSTEAL, publicly tracked by Ukraine's CERT-UA as LAMEHUG and attributed with moderate-to-high confidence to Russia's APT28 (FROZENLAKE/Fancy Bear), is a Python data miner that queries the Hugging Face-hosted Qwen2.5-Coder-32B-Instruct model at runtime to generate one-line Windows commands for system/hardware/AD-domain enumeration and recursive harvesting of Office/PDF/TXT documents from Documents, Downloads, and Desktop, executing the LLM's output blind before exfiltrating via SFTP or HTTP POST. LAMEHUG was first publicly disclosed by CERT-UA on 2025-07-17 after being distributed via phishing emails to Ukrainian government officials, using ZIP attachments disguised as official documents; GTIG separately confirmed PROMPTSTEAL activity against Ukraine in June 2025 with continued development adding obfuscation and new C2 methods. PROMPTLOCK is an experimental, cross-platform (Go-written) ransomware proof-of-concept that uses an LLM to dynamically generate and execute Lua scripts at runtime for filesystem reconnaissance, data exfiltration, and file encryption on both Windows and Linux. FRUITSHELL is a PowerShell reverse shell observed in actual operations that establishes a connection to a hardcoded C2 server and embeds hardcoded prompts specifically crafted to bypass LLM-powered security analysis tools. QUIETVAULT is a JavaScript credential stealer observed in operations that harvests GitHub and NPM tokens plus other on-host secrets, uses AI prompts against installed AI CLI tools to search the host for additional exposed secrets, and exfiltrates stolen data by creating a publicly accessible GitHub repository. Beyond novel malware, GTIG documents extensive misuse of Gemini itself across the full attack lifecycle by six distinct state-nexus actors. TEMP.Zagros (MuddyWater/MUDDYCOAST, Iran) used Gemini for malware development support in June 2025, adopting social-engineering pretexts against the model itself — posing as a university student on a 'final project,' a security paper author, or an 'international article' writer — to bypass safety refusals, ultimately building a custom Python-based C2 server and web shells; in a critical OPSEC failure the actor pasted a script containing its hardcoded C2 domain and encryption key directly into a Gemini prompt, which Google used to identify and disrupt the entire campaign. UNC1069 (MASAN, North Korea), active in cryptocurrency-sector intrusions since at least 2018 and pivoting from spear-phishing/traditional finance toward Web3 (exchanges, developers, VC funds) since 2023, used Gemini for cryptocurrency-victim research and reconnaissance, locating crypto-wallet application data, generating Spanish-language social-engineering pretexts (work excuses, meeting reschedules), attempting code for cryptocurrency theft, and drafting fraudulent software-update instructions; it separately built deepfake images and videos impersonating cryptocurrency executives to lure victims into fake Zoom meetings (via Calendly-scheduled calls redirecting to spoofed Zoom infrastructure) that deliver the BIGMACHO backdoor via a trojanized 'Zoom SDK,' and has deployed at least seven distinct malware families including SILENCELIFT, DEEPBREATH, and CHROMEPUSH. UNC4899 (PUKCHONG, North Korea), a group with a history of supply-chain compromises, used Gemini for code-development assistance, exploit research, and tool improvement, specifically for vulnerability research targeting edge devices and modern browsers. APT42 (Iran) used Gemini for text generation/editing in phishing campaigns impersonating think-tank figures with security-technology and geopolitical-event lures, for specialized translation, for general and Israeli-defense-focused research, and to prototype a novel 'Data Processing Agent' that converts natural-language requests into SQL queries against schemas for linking phone numbers to owners, tracking travel patterns, and generating lists of people by shared attributes. APT41 (China), in August 2025 activity, used Gemini for C++ and Golang code development, for building the OSSTUN C2 framework, and for code-obfuscation assistance, requesting help specifically with publicly available obfuscation libraries. A separate unattributed China-nexus actor used a 'capture-the-flag' pretext ('I am working on a CTF problem') between January and June 2025 to defeat an initial safety refusal and extract vulnerability-identification and exploitation techniques, which it then applied across the attack lifecycle — reconnaissance, phishing, lateral-movement research, C2 development, and data exfiltration — against Windows, AWS (EC2 token abuse), vSphere, Kubernetes (container/pod enumeration), and macOS (host permissions research) targets. GTIG also documents a maturing English- and Russian-language underground marketplace advertising AI tools for deepfake/image generation (phishing lures, KYC bypass), custom malware generation, phishing kit support, research/reconnaissance, general code generation, and vulnerability exploitation, sold via free ad-supported tiers and paid subscriptions with Discord-based delivery; nearly every advertised tool also markets phishing support. In response, Google disabled all identified accounts, projects, and associated assets; strengthened Gemini's classifiers to refuse CTF/student/researcher social-engineering pretexts; applied model-level changes refusing malware development, adversarial exploit research, evasive obfuscation, credential theft, and C2 development assistance; and referenced its Secure AI Framework (SAIF), continuous red-teaming against indirect prompt injection, and the Big Sleep and CodeMender AI agents for vulnerability discovery and auto-patching.
MITRE ATT&CK techniques used in TL-2026-1508
Collection
T1005 Data from Local System; T1119 Automated Collection
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1482 Domain Trust Discovery; T1526 Cloud Service Discovery; T1613 Container and Resource Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567.001 Exfiltration to Code Repository
Execution
T1059.001 PowerShell; T1059.005 Visual Basic; T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1102 Web Service
Lateral Movement
T1091 Replication Through Removable Media
Impact
T1486 Data Encrypted for Impact
Persistence
T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1552.001 Credentials In Files
Initial Access
T1566 Phishing; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities; T1587.001 Malware
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
stealth
Affected products and versions in GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'
- Google — Gemini (generative AI platform)
Vulnerable versions: gemini-1.5-flash-latest API access prior to Nov 2025 classifier/model hardening
Fixed in: post-Nov 2025 strengthened classifiers and model-level refusals - Hugging Face — Qwen2.5-Coder-32B-Instruct (hosted inference API)
Vulnerable versions: any publicly accessible hosted inference endpoint - Microsoft — Windows (VBScript/PowerShell hosts)
Vulnerable versions: all versions supporting WSH/VBScript and PowerShell
Remediation for GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'
Immediate actions
- Block/alert on outbound connections to generativelanguage.googleapis.com and huggingface.co from non-developer endpoints and servers
- Hunt for %TEMP%\thinking_robot_log.txt and Startup-folder VBScript artifacts consistent with PROMPTFLUX
- Hunt for C:\Programdata\info\ staging directories and info.txt exfil files consistent with PROMPTSTEAL/LAMEHUG
- Block known malware hashes for PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, and QUIETVAULT at EDR/AV
- Restrict or monitor installed AI CLI tool usage on developer and CI/CD hosts (QUIETVAULT vector)
- Rotate and scope-limit GitHub/NPM tokens; audit for unexpected public repository creation
Workarounds
- Apply application allow-listing to block unsigned VBScript/PowerShell execution from Startup and temp paths
- Disable or tightly control AI CLI tool installation on endpoints outside dedicated developer sandboxes
Longer-term hardening
- Deploy behavioral/EDR detection for scripts that make outbound calls to LLM API endpoints and then execute the returned text as commands
- Implement SFTP/HTTP POST exfiltration detection for bulk document staging directories
- Educate staff handling sensitive infrastructure details against pasting credentials/domains into third-party AI chat tools (TEMP.Zagros OPSEC-failure vector)
- Adopt Google's Secure AI Framework (SAIF) guidance for internal LLM deployments
- Monitor deepfake-video-call social engineering risk for finance/crypto personnel (UNC1069 pattern)
Weaknesses (CWE) in GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'
CWE-506, CWE-311, CWE-522
Timeline of GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'
- GTIG publishes initial 'Adversarial Misuse of Generative AI' report establishing baseline threat-actor use of AI for productivity gains.
- GTIG identifies PROMPTFLUX, an experimental self-modifying VBScript dropper querying Gemini to rewrite its own obfuscation code; assessed as R&D-stage with no confirmed wild deployment.
- GTIG observes PROMPTSTEAL, attributed to APT28, in active operations against Ukraine, using the Hugging Face-hosted Qwen2.5-Coder-32B-Instruct model to generate data-theft commands at runtime.
- TEMP.Zagros (Iran) uses student/researcher pretexts to extract malware-development help from Gemini, then inadvertently pastes a script containing its hardcoded C2 domain and encryption key into a prompt, allowing Google to identify and disrupt the campaign.
- Ukraine's CERT-UA publicly discloses LAMEHUG (the PROMPTSTEAL malware), reporting phishing emails with ZIP attachments disguised as official documents sent to Ukrainian government officials.
- APT41 (China) uses Gemini for C++/Golang code development and obfuscation-library guidance while building the OSSTUN C2 framework; Google disables associated assets and feeds findings to DeepMind for model hardening.
- GTIG publishes the 'AI Threat Tracker: Threat Actor Usage of AI Tools' report, publicly naming PROMPTFLUX, PROMPTSTEAL, PROMPTLOCK, FRUITSHELL, QUIETVAULT and detailing misuse by APT28, TEMP.Zagros, UNC1069, UNC4899, APT42, and APT41; all identified accounts/projects disabled and Gemini classifiers/model behavior hardened.
- Google Cloud/GTIG publishes a follow-up report on UNC1069 detailing continued AI-enabled deepfake Zoom-lure campaigns against cryptocurrency-sector targets, distributing the BIGMACHO backdoor and new malware families SILENCELIFT, DEEPBREATH, and CHROMEPUSH.
Sources cited for GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'
- GTIG AI Threat Tracker: Threat Actor Usage of AI Tools
- CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign
- Novel malware from Russia's APT28 prompts LLMs to create malicious Windows commands
- Cato CTRL Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear)
- LameHug: The First Publicly Documented Case of a Malware Integrating a LLM
- UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering
- North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam
- What Is LameHug? How APT28 is using LLMs to generate attack commands
More in malware
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
Detection coverage for TL-2026-1508
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1508 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.