Ever heard of PromptFlux and PromptSteal? Sounds like some high-tech sci-fi project, right? But nope — these two aren’t cool experiments; they’re actually new malware that are pretty creepy.
Why? Because both of them already use AI and large language models (LLMs) like Gemini and Qwen to do their thing. So they don’t just spread and wreck systems like normal viruses — they can actually think and adapt.
PromptFlux: The Shape-Shifting Malware
PromptFlux is like a digital chameleon. Every time it runs, it tweaks its own code through the Gemini API. That means the unique signature antivirus programs usually rely on won’t recognize it anymore.
Just imagine — every time it gets spotted, it instantly changes its color and pattern, like playing hide and seek with security systems. It’s super hard to detect because it never looks the same twice.
PromptSteal: Out in the Wild
While PromptFlux is still in the experimental phase, PromptSteal is already out there in the real world. Google reported that this malware was used by Russian hackers (APT28) to steal data from victims’ computers.
What makes it even scarier is that PromptSteal uses Qwen AI to automatically write Windows command line instructions. Since the commands change every time it runs, there’s no consistent pattern for security systems to catch. The result? This malware can quietly run in the background and vanish without leaving any clear trace.
The Cyber World Will Never Be the Same
These two malware are clear proof that we’ve entered a new era of cybersecurity. Now, malware isn’t just made by humans — it’s also powered by AI.
That means traditional antivirus software that only depends on signatures just isn’t enough anymore. It’s time to switch to systems that can detect strange behavior — like constantly changing files, scripts calling AI APIs, or suspicious connections to unknown servers.
So, What Can You Do?
If you work in the digital world — whether you’re a developer, server admin, or manage websites — now’s the time to be extra careful.
Here’s what you can do:
- Don’t install random scripts or plugins from unknown sources.
- Keep your system and security software up to date.
- Limit API access — especially ones connected to external AI services.
- Regularly check server activity and outgoing connection logs.
Because once malware starts using AI, the impact can be way worse than old-school viruses. So yeah, like it or not, we’ve gotta be smarter than the malware that can “think.”