Advanced AI-powered malware is increasingly challenging security defenses This article explores malware increasingly. . Unlike traditional threats that evolve by changing their code, these programs can alter their appearance frequently while maintaining their harmful intent.

A malicious dropper can request a new, concealed version of itself at regular intervals, and related tools can generate quick commands for collecting documents. Morphisec analysts observed the shift following an examination of PROMPTFLUX, an experimental dropper revealed by Google's threat researchers in late 2025. The sample reportedly queried the Gemini API once every hour and regenerated obfuscated code, with researchers identifying over 70 variants in just four hours. In a report shared with ZeroOwl (ZeroOwl), Morphisec noted that the primary concern is not a confirmed mass campaign but the pressure this places on signature-based controls.

However, defenders should not assume a clean scan indicates a program is safe, especially when it includes scripts, uses built-in tools, or operates primarily in memory. Keep operating systems and internet-facing applications patched, restrict unnecessary scripting and administrative utilities, and investigate unusual child processes or commands that access large document collections. Analysts should focus on identifying the underlying actions, such as suspicious credential access, unexpected archive creation, outbound connections, or unusual use of trusted tools, rather than relying solely on filenames or hashes.

Securely integrate threat intelligence platforms like MISP, VirusTotal, or your SIEM.