Bitcoin
Bitcoin (BTC)
$100,429.00 -2.83295
Bitcoin price
Ethereum
Ethereum (ETH)
$3,241.64 -4.46349
Ethereum price
BNB
BNB (BNB)
$937.31 -1.11427
BNB price
Solana
Solana (SOL)
$152.50 -5.11798
Solana price
XRP
XRP (XRP)
$2.19 -5.03228
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000092 1.38365
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000056 0.48187
Pepe price
Bonk
Bonk (BONK)
$0.000012 -0.87628
Bonk price
dogwifhat
dogwifhat (WIF)
$0.431452 0.36665
dogwifhat price
Popcat
Popcat (POPCAT)
$0.130273 -0.39216
Popcat price
Bitcoin
Bitcoin (BTC)
$100,429.00 -2.83295
Bitcoin price
Ethereum
Ethereum (ETH)
$3,241.64 -4.46349
Ethereum price
BNB
BNB (BNB)
$937.31 -1.11427
BNB price
Solana
Solana (SOL)
$152.50 -5.11798
Solana price
XRP
XRP (XRP)
$2.19 -5.03228
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000092 1.38365
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000056 0.48187
Pepe price
Bonk
Bonk (BONK)
$0.000012 -0.87628
Bonk price
dogwifhat
dogwifhat (WIF)
$0.431452 0.36665
dogwifhat price
Popcat
Popcat (POPCAT)
$0.130273 -0.39216
Popcat price
Bitcoin
Bitcoin (BTC)
$100,429.00 -2.83295
Bitcoin price
Ethereum
Ethereum (ETH)
$3,241.64 -4.46349
Ethereum price
BNB
BNB (BNB)
$937.31 -1.11427
BNB price
Solana
Solana (SOL)
$152.50 -5.11798
Solana price
XRP
XRP (XRP)
$2.19 -5.03228
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000092 1.38365
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000056 0.48187
Pepe price
Bonk
Bonk (BONK)
$0.000012 -0.87628
Bonk price
dogwifhat
dogwifhat (WIF)
$0.431452 0.36665
dogwifhat price
Popcat
Popcat (POPCAT)
$0.130273 -0.39216
Popcat price
Bitcoin
Bitcoin (BTC)
$100,429.00 -2.83295
Bitcoin price
Ethereum
Ethereum (ETH)
$3,241.64 -4.46349
Ethereum price
BNB
BNB (BNB)
$937.31 -1.11427
BNB price
Solana
Solana (SOL)
$152.50 -5.11798
Solana price
XRP
XRP (XRP)
$2.19 -5.03228
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000092 1.38365
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000056 0.48187
Pepe price
Bonk
Bonk (BONK)
$0.000012 -0.87628
Bonk price
dogwifhat
dogwifhat (WIF)
$0.431452 0.36665
dogwifhat price
Popcat
Popcat (POPCAT)
$0.130273 -0.39216
Popcat price

Google flags 5 AI-powered malware families linked to DPRK crypto theft

Dorian Batycka
Edited by
News
crypto theft

A new GTIG report reveals that cybercriminals are increasingly using LLMs to make malware smarter, allowing it to rewrite itself in real time and target high-value assets like crypto.

Summary
  • 5 distinct AI-enabled malware families dynamically query LLMs like Gemini and Qwen2.5-Coder to modify or create code during runtime.
  • North Korean group UNC1069 (Masan) is exploiting AI to probe crypto wallets and create phishing scripts.
  • Google has disabled accounts linked to these activities and strengthened safeguards with enhanced API monitoring and prompt filters.

A new report from Google’s Threat Intelligence Group has uncovered a growing trend in which cybercriminals and state-linked actors are using large language models to supercharge their malware operations.

The report identified 5 distinct families of AI-enabled malware that query LLMs like Gemini and Qwen2.5-Coder during runtime to generate, modify or hide malicious code.

Among the identified threats, two malware families PROMPTFLUX and PROMPTSTEAL were examined in detail. PROMPTFLUX uses a “Thinking Robot” process that calls Gemini’s API hourly to rewrite its VBScript code. PROMPTSTEAL, linked to the Russian APT28 group, leverages the Qwen model hosted on Hugging Face to generate Windows commands on demand, which allows attackers to execute customized operations without pre-programming each function.

This “just-in-time code creation” technique enables the malware to modify its behavior in real time, marking a shift from traditional malware creation, which relies on hard-coded logic.

AI-enabled malware exploits LLMs for crypto theft

The report noted that these AI-driven attacks are already active and targeting high-value assets, including crypto holdings.

It also found that the North Korean group UNC1069 (a.k.a. Masan) has been misusing AI to conduct crypto theft by probing crypto wallets, creating phishing scripts, and crafting targeted social engineering attacks.

Google has disabled accounts tied to these activities and implemented stricter safeguards, including enhanced API monitoring and prompt filters, to limit AI misuse.