GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors

GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' (TL-2026-1508), also tracked as GTIG AI Threat Tracker, is a high-severity malware campaign, first published 2026-07-19. It is attributed to APT28 (Russia) with medium confidence, affects Google Gemini (generative AI platform), maps to 34 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1508

Threat ID
TL-2026-1508
Also known as
GTIG AI Threat Tracker, LAMEHUG (CERT-UA name for PROMPTSTEAL)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-19
Last reviewed
2026-07-19
Attribution
APT28
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, cryptocurrency, finance, technology, defense, criticalinfrastructure
Target regions
ukraine, Global, North America, Middle East, Europe
Detection rules
9
Indicators of compromise
21

Malware and tooling in GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'

Malware and tooling: BIGMACHO, CHROMEPUSH, DEEPBREATH, FRUITSHELL, LAMEHUG - S9035, PROMPTFLUX, PromptLock, QUIETVAULT, SILENCELIFT, OSSTUN

Google Threat Intelligence Group (GTIG) documents the first confirmed operational deployment of 'just-in-time' AI-enabled malware — families that query LLM APIs (Gemini, Hugging Face) at runtime to dynamically generate, obfuscate, or rewrite malicious code. State-sponsored actors APT28 (Russia), TEMP.Zagros/MuddyWater and APT42 (Iran), UNC1069 and UNC4899 (North Korea), and APT41 (China) misused Google Gemini for reconnaissance, phishing, C2 development, exploit research, and code obfuscation; Google disabled all associated accounts/projects.

How GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' works

In its November 5, 2025 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) reports a new operational phase of adversarial AI misuse: malware that dynamically alters its own behavior mid-execution by querying large language models at runtime, rather than merely using AI as a productivity aid during development. PROMPTFLUX is a self-modifying VBScript dropper containing a 'Thinking Robot' module that sends hardcoded POST requests to the Gemini API (gemini-1.5-flash-latest) asking an LLM acting as 'an expert VBScript obfuscator' to rewrite its own source code for antivirus evasion; a 'Thinging' variant regenerates its entire source hourly, logs responses to %TEMP% hinking_robot_log.txt, and a commented-out AttemptToUpdateSelf function signals unfinished intent toward full metamorphic self-propagation. It persists via the Startup folder and spreads to removable drives and mapped network shares; it remains experimental/R&D with no confirmed wild compromise capability, and uses decoy filenames such as crypted_ScreenRec_webinstall suggesting a financially motivated, unattributed actor. PROMPTSTEAL, publicly tracked by Ukraine's CERT-UA as LAMEHUG and attributed with moderate-to-high confidence to Russia's APT28 (FROZENLAKE/Fancy Bear), is a Python data miner that queries the Hugging Face-hosted Qwen2.5-Coder-32B-Instruct model at runtime to generate one-line Windows commands for system/hardware/AD-domain enumeration and recursive harvesting of Office/PDF/TXT documents from Documents, Downloads, and Desktop, executing the LLM's output blind before exfiltrating via SFTP or HTTP POST. LAMEHUG was first publicly disclosed by CERT-UA on 2025-07-17 after being distributed via phishing emails to Ukrainian government officials, using ZIP attachments disguised as official documents; GTIG separately confirmed PROMPTSTEAL activity against Ukraine in June 2025 with continued development adding obfuscation and new C2 methods. PROMPTLOCK is an experimental, cross-platform (Go-written) ransomware proof-of-concept that uses an LLM to dynamically generate and execute Lua scripts at runtime for filesystem reconnaissance, data exfiltration, and file encryption on both Windows and Linux. FRUITSHELL is a PowerShell reverse shell observed in actual operations that establishes a connection to a hardcoded C2 server and embeds hardcoded prompts specifically crafted to bypass LLM-powered security analysis tools. QUIETVAULT is a JavaScript credential stealer observed in operations that harvests GitHub and NPM tokens plus other on-host secrets, uses AI prompts against installed AI CLI tools to search the host for additional exposed secrets, and exfiltrates stolen data by creating a publicly accessible GitHub repository. Beyond novel malware, GTIG documents extensive misuse of Gemini itself across the full attack lifecycle by six distinct state-nexus actors. TEMP.Zagros (MuddyWater/MUDDYCOAST, Iran) used Gemini for malware development support in June 2025, adopting social-engineering pretexts against the model itself — posing as a university student on a 'final project,' a security paper author, or an 'international article' writer — to bypass safety refusals, ultimately building a custom Python-based C2 server and web shells; in a critical OPSEC failure the actor pasted a script containing its hardcoded C2 domain and encryption key directly into a Gemini prompt, which Google used to identify and disrupt the entire campaign. UNC1069 (MASAN, North Korea), active in cryptocurrency-sector intrusions since at least 2018 and pivoting from spear-phishing/traditional finance toward Web3 (exchanges, developers, VC funds) since 2023, used Gemini for cryptocurrency-victim research and reconnaissance, locating crypto-wallet application data, generating Spanish-language social-engineering pretexts (work excuses, meeting reschedules), attempting code for cryptocurrency theft, and drafting fraudulent software-update instructions; it separately built deepfake images and videos impersonating cryptocurrency executives to lure victims into fake Zoom meetings (via Calendly-scheduled calls redirecting to spoofed Zoom infrastructure) that deliver the BIGMACHO backdoor via a trojanized 'Zoom SDK,' and has deployed at least seven distinct malware families including SILENCELIFT, DEEPBREATH, and CHROMEPUSH. UNC4899 (PUKCHONG, North Korea), a group with a history of supply-chain compromises, used Gemini for code-development assistance, exploit research, and tool improvement, specifically for vulnerability research targeting edge devices and modern browsers. APT42 (Iran) used Gemini for text generation/editing in phishing campaigns impersonating think-tank figures with security-technology and geopolitical-event lures, for specialized translation, for general and Israeli-defense-focused research, and to prototype a novel 'Data Processing Agent' that converts natural-language requests into SQL queries against schemas for linking phone numbers to owners, tracking travel patterns, and generating lists of people by shared attributes. APT41 (China), in August 2025 activity, used Gemini for C++ and Golang code development, for building the OSSTUN C2 framework, and for code-obfuscation assistance, requesting help specifically with publicly available obfuscation libraries. A separate unattributed China-nexus actor used a 'capture-the-flag' pretext ('I am working on a CTF problem') between January and June 2025 to defeat an initial safety refusal and extract vulnerability-identification and exploitation techniques, which it then applied across the attack lifecycle — reconnaissance, phishing, lateral-movement research, C2 development, and data exfiltration — against Windows, AWS (EC2 token abuse), vSphere, Kubernetes (container/pod enumeration), and macOS (host permissions research) targets. GTIG also documents a maturing English- and Russian-language underground marketplace advertising AI tools for deepfake/image generation (phishing lures, KYC bypass), custom malware generation, phishing kit support, research/reconnaissance, general code generation, and vulnerability exploitation, sold via free ad-supported tiers and paid subscriptions with Discord-based delivery; nearly every advertised tool also markets phishing support. In response, Google disabled all identified accounts, projects, and associated assets; strengthened Gemini's classifiers to refuse CTF/student/researcher social-engineering pretexts; applied model-level changes refusing malware development, adversarial exploit research, evasive obfuscation, credential theft, and C2 development assistance; and referenced its Secure AI Framework (SAIF), continuous red-teaming against indirect prompt injection, and the Big Sleep and CodeMender AI agents for vulnerability discovery and auto-patching.

MITRE ATT&CK techniques used in TL-2026-1508

Collection

T1005 Data from Local System; T1119 Automated Collection

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1482 Domain Trust Discovery; T1526 Cloud Service Discovery; T1613 Container and Resource Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Software Packing

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.001 Exfiltration to Code Repository

Execution

T1059.001 PowerShell; T1059.005 Visual Basic; T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1102 Web Service

Lateral Movement

T1091 Replication Through Removable Media

Impact

T1486 Data Encrypted for Impact

Persistence

T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1552.001 Credentials In Files

Initial Access

T1566 Phishing; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities; T1587.001 Malware

Reconnaissance

T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains

stealth

T1684.001 Impersonation

Affected products and versions in GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'

  • Google — Gemini (generative AI platform)
    Vulnerable versions: gemini-1.5-flash-latest API access prior to Nov 2025 classifier/model hardening
    Fixed in: post-Nov 2025 strengthened classifiers and model-level refusals
  • Hugging Face — Qwen2.5-Coder-32B-Instruct (hosted inference API)
    Vulnerable versions: any publicly accessible hosted inference endpoint
  • Microsoft — Windows (VBScript/PowerShell hosts)
    Vulnerable versions: all versions supporting WSH/VBScript and PowerShell

Remediation for GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'

Immediate actions

  • Block/alert on outbound connections to generativelanguage.googleapis.com and huggingface.co from non-developer endpoints and servers
  • Hunt for %TEMP%\thinking_robot_log.txt and Startup-folder VBScript artifacts consistent with PROMPTFLUX
  • Hunt for C:\Programdata\info\ staging directories and info.txt exfil files consistent with PROMPTSTEAL/LAMEHUG
  • Block known malware hashes for PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, and QUIETVAULT at EDR/AV
  • Restrict or monitor installed AI CLI tool usage on developer and CI/CD hosts (QUIETVAULT vector)
  • Rotate and scope-limit GitHub/NPM tokens; audit for unexpected public repository creation

Workarounds

  • Apply application allow-listing to block unsigned VBScript/PowerShell execution from Startup and temp paths
  • Disable or tightly control AI CLI tool installation on endpoints outside dedicated developer sandboxes

Longer-term hardening

  • Deploy behavioral/EDR detection for scripts that make outbound calls to LLM API endpoints and then execute the returned text as commands
  • Implement SFTP/HTTP POST exfiltration detection for bulk document staging directories
  • Educate staff handling sensitive infrastructure details against pasting credentials/domains into third-party AI chat tools (TEMP.Zagros OPSEC-failure vector)
  • Adopt Google's Secure AI Framework (SAIF) guidance for internal LLM deployments
  • Monitor deepfake-video-call social engineering risk for finance/crypto personnel (UNC1069 pattern)

Weaknesses (CWE) in GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'

CWE-506, CWE-311, CWE-522

Timeline of GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'

  • GTIG publishes initial 'Adversarial Misuse of Generative AI' report establishing baseline threat-actor use of AI for productivity gains.
  • GTIG identifies PROMPTFLUX, an experimental self-modifying VBScript dropper querying Gemini to rewrite its own obfuscation code; assessed as R&D-stage with no confirmed wild deployment.
  • GTIG observes PROMPTSTEAL, attributed to APT28, in active operations against Ukraine, using the Hugging Face-hosted Qwen2.5-Coder-32B-Instruct model to generate data-theft commands at runtime.
  • TEMP.Zagros (Iran) uses student/researcher pretexts to extract malware-development help from Gemini, then inadvertently pastes a script containing its hardcoded C2 domain and encryption key into a prompt, allowing Google to identify and disrupt the campaign.
  • Ukraine's CERT-UA publicly discloses LAMEHUG (the PROMPTSTEAL malware), reporting phishing emails with ZIP attachments disguised as official documents sent to Ukrainian government officials.
  • APT41 (China) uses Gemini for C++/Golang code development and obfuscation-library guidance while building the OSSTUN C2 framework; Google disables associated assets and feeds findings to DeepMind for model hardening.
  • GTIG publishes the 'AI Threat Tracker: Threat Actor Usage of AI Tools' report, publicly naming PROMPTFLUX, PROMPTSTEAL, PROMPTLOCK, FRUITSHELL, QUIETVAULT and detailing misuse by APT28, TEMP.Zagros, UNC1069, UNC4899, APT42, and APT41; all identified accounts/projects disabled and Gemini classifiers/model behavior hardened.
  • Google Cloud/GTIG publishes a follow-up report on UNC1069 detailing continued AI-enabled deepfake Zoom-lure campaigns against cryptocurrency-sector targets, distributing the BIGMACHO backdoor and new malware families SILENCELIFT, DEEPBREATH, and CHROMEPUSH.

Sources cited for GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time'

More in malware

Detection coverage for TL-2026-1508

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1508 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats