GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors — Threadlinqs Intelligence
As of 2026-07-19, GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors is a high-severity malware threat attributed to APT28 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1508 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: APT28 · Russia · ESPIONAGE
Google Threat Intelligence Group (GTIG) documents the first confirmed operational deployment of 'just-in-time' AI-enabled malware — families that query LLM APIs (Gemini, Hugging Face) at runtime to
In its November 5, 2025 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) reports a new operational phase of adversarial AI misuse: malware that dynamically alters its own behavior mid-execution by querying large language models at runtime, rather than merely using AI as a productivity aid during development. PROMPTFLUX is a self-modifying VBScript dropper containing a 'Thinking Robot' module that sends hardcoded POST requests to the Gemini API (gemini-1.5-flash-latest) asking an LLM acting as 'an expert VBScript obfuscator' to rewrite its own source code for antivirus evasion; a 'Thinging' variant regenerates its entire source hourly, logs responses to %TEMP% hinking_robot_log.txt, and a commented-out AttemptToUpdateSelf function signals unfinished intent toward full metamorphic self-propagation. It persists via the Startup folder and spreads to removable drives and mapped network shares; it remains experimental/R&D with no confirmed wild compromise capability, and uses decoy filenames such as crypted_ScreenRec_webinstall suggesting a financially motivated, unattributed actor. PROMPTSTEAL, publicly tracked by Ukraine's CERT-UA as LAMEHUG and attributed with moderate-to-high confidence to Russia's APT28 (FROZENLAKE/Fancy Bear), is a Python data miner that queries the Hugging Face-hosted Qwen2.5-Coder-32B-Instruct model at runtime to generate one-line Windows commands for system/hardware/AD-domain enumeration and recursive harvesting of Office/PDF/TXT documents from Documents, Downloads, and Desktop, executing the LLM's output blind before exfiltrating via SFTP or HTTP POST. LAMEHUG was first publicly disclosed by CERT-UA on 2025-07-17 after being distributed via phishing emails to Ukrainian government officials, using ZIP attachments disguised as official documents; GTIG separately confirmed PROMPTSTEAL activity against Ukraine in June 2025 with continued development adding obfuscation and new C2 methods. PROMPTLOCK is an experimental, cross-platform (Go-written) ransomware proof-of-concept that uses an LLM to dynamically generate and execute Lua scripts at runtime for filesystem reconnaissance, data exfiltration, and file encryption on both Windows and Linux. FRUITSHELL is a PowerShell reverse shell observed in actual operations that establishes a connection to a hardcoded C2 server and embeds hardcoded prompts specifically crafted to bypass LLM-powered security analysis tools. QUIETVAULT is a JavaScript credential stealer observed in operations that harvests GitHub and NPM tokens plus other on-host secrets, uses AI prompts against installed AI CLI tools to search the host for additional exposed secrets, and exfiltrates stolen data by creating a publicly accessible GitHub repository. Beyond novel malware, GTIG documents extensive misuse of Gemini itself across the full attack lifecycle by six distinct state-nexus actors. TEMP.Zagros (MuddyWater/MUDDYCOAST, Iran) used Gemini for malware development support in June 2025, adopting social-engineering pretexts against the model itself — posing as a university student on a 'final project,' a security paper author, or an 'international article' writer — to bypass safety refusals, ultimately building a custom Python-based C2 server and web shells; in a critical OPSEC failure the actor pasted a script containing its hardcoded C2 domain and encryption key directly into a Gemini prompt, which Google used to identify and disrupt the entire campaign. UNC1069 (MASAN, North Korea), active in cryptocurrency-sector intrusions since at least 2018 and pivoting from spear-phishing/traditional finance toward Web3 (exchanges, developers, VC funds) since 2023, used Gemini for cryptocurrency-victim research and reconnaissance, locating crypto-wallet application data, generating Spanish-language social-engineering pretexts (work excuses, meeting reschedules), attempting code for cryptocurrency theft, and drafting fraudulent software-update instructions; it separately built deepfake images
Weaknesses (CWE)
CWE-506, CWE-311, CWE-522
Target sectors: government administration, cryptocurrency, finance, technology, defense, criticalinfrastructure
Target regions: ukraine, Global, North America, Middle East, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1587, T1587.001, T1583, T1584, T1589, T1593, T1566, T1566.001, T1566.002, T1059.005