News Room
16
Share
Emerging 'PromptFlux' Variant Leverages Real-Time LLM Code Injection for Stealthy Persistence
highAI Cyber Attacks

Emerging 'PromptFlux' Variant Leverages Real-Time LLM Code Injection for Stealthy Persistence

Security researchers have identified a new iteration of the PromptFlux malware that utilizes live API calls to LLMs to rewrite its own source code, effectively bypassing traditional signature-based detection.

30 September 2026Last updated 30 September 20264 min readGoogle Threat Intelligence Group
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
High
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
High Confidence
Source:
Google Threat Intelligence Group
Read Time:
4 min

Executive Summary

Recent intelligence indicates a significant evolution in autonomous malware capabilities. A new variant of the 'PromptFlux' dropper has been observed in the wild, utilizing real-time integration with Large Language Models (LLMs) to perform on-the-fly code obfuscation and polymorphic behavior. This development marks a shift from static AI-assisted malware to dynamic, agentic payloads that adapt their execution logic during the infection lifecycle.

Threat Analysis

The threat actor, currently tracked as 'Nebula-X', is leveraging this LLM-powered mechanism to maintain persistence within enterprise environments. Unlike traditional malware that relies on pre-compiled obfuscation, this variant sends its own source code to an external LLM API, requesting functional variations that maintain malicious intent while altering the file hash. This allows the malware to evade endpoint detection and response (EDR) systems that rely on static file analysis.

Technical Details

PromptFlux operates as a VBScript-based dropper. Upon initial execution, it establishes a connection to a compromised API endpoint that proxies requests to a frontier LLM. The script transmits its current payload and receives a rewritten, functionally equivalent version. This new iteration is then saved to the Windows Startup folder. The malware also exhibits lateral movement capabilities by scanning for mapped network shares and removable drives, where it attempts to replicate using the same LLM-assisted obfuscation technique. The use of the Google Gemini API has been noted in previous iterations, though current samples suggest a shift toward private, fine-tuned models to avoid rate-limiting and safety filters.

Attribution Assessment

While the specific identity of the operators remains unconfirmed, the sophistication of the API integration and the rapid iteration cycle suggest a well-resourced cybercriminal group. The techniques align with recent observations of 'agentic' attack chains where attackers provide a high-level objective to an LLM, which then autonomously manages the reconnaissance and exploitation phases.

Implications

This trend represents a critical challenge for security operations centers (SOCs). Traditional signature-based defenses are rendered ineffective by the malware's ability to regenerate its own code. Organizations must shift toward behavioral analysis and network-level traffic inspection to identify the anomalous API calls that facilitate this 'live' code generation.

Recommendations

  1. Implement strict egress filtering to block unauthorized API calls to known LLM providers from non-authorized endpoints. 2. Deploy behavioral monitoring tools capable of detecting anomalous script execution patterns. 3. Enforce strict least-privilege access for service accounts to prevent the malware from accessing network shares. 4. Conduct regular threat hunting exercises focused on identifying unauthorized VBScript activity.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo