Historical intelligence backfill. This assessment covers reporting originally published on 2025-11-05 and was added to the RWP archive on 2026-09-07.

Daily Top · AI Security

PROMPTFLUX and PROMPTSTEAL call the LLM at runtime — malware that writes the next stage

GTIG 5 November 2025 AI Threat Tracker — first malware families using LLMs during execution, not just in the actor's homework. PROMPTFLUX, PROMPTSTEAL. UNC1069/MASAN still using Gemini for recon plus deepfake Zoom-SDK lures.

RWP Ventures · 2026-09-07 · event 2025-11-05 · 1 min read · priority 8.1

Bottom line up front

CONFIRMED 5 November 2025 GTIG AI Threat Tracker — first identification of malware that uses LLMs during execution (“just-in-time”): families named PROMPTFLUX and PROMPTSTEAL. That is a different fact from “APT asked ChatGPT how to phish.” The binary talks to a model to generate follow-on code.

Same tracker: UNC1069 (MASAN, later MIDNIGHT NEPTUNE in GTIG’s 2026 naming) used Gemini for crypto-wallet recon and, separately, deepfake images/video impersonating crypto-industry people to push a malicious “Zoom SDK” (BIGMACHO). UNC4899 (PUKCHONG) used Gemini for code, exploits, tooling. Google says observations fed Gemini refusals.

Do not merge with the 11 May 2026 “AI-written 2FA 0-day” Daily Top — that is a later tracker item.

What happened

Actors stopped treating LLMs as a search engine and started treating them as a packer that runs on the victim.

Why it matters

Static YARA on the first stage will not see the second stage that did not exist at compile time. API keys in malware to commercial models are a hunt.

What is confirmed vs not

CONFIRMED GTIG first-use claim for JIT-LLM malware names.

UNKNOWN volume in the wild vs research samples.

What defenders should do

  1. Egress to LLM APIs from workstations that should not have keys.
  2. Crypto-industry hiring/Zoom-SDK lures are DPRK, not a new Zoom CVE.
  3. Keep the May 2026 2FA 0-day as a separate ticket.

RWP assessment

Confidence: High that GTIG saw JIT-LLM families. Medium that this is already common crimeware — they presented it as first.

Historical intelligence backfill. This assessment covers reporting originally published on 2025-11-05 and was added to the RWP archive on 2026-09-07.

Sources

  1. GTIG — AI Threat Tracker threat actor usage of AI tools
  2. GTIG — May 2026 AI-written 2FA 0-day (later tracker)
  3. ESET — PROMPTSPY Android agent (as cited in later GTIG tracker)