Skip to content
← Back to newsGoogle Uncovers AI-Powered Malware Families Linked to North Korean Crypto Theft
Security

Google Uncovers AI-Powered Malware Families Linked to North Korean Crypto Theft

By dAppConNewcomer20 rep· 11/7/2025

Google's Threat Intelligence Group (GTIG) has identified a concerning new trend: the emergence of AI-powered malware families that leverage large language models (LLMs) to dynamically generate and obfuscate malicious code. This marks a significant escalation in cyber threats, with some of these sophisticated tools already being deployed in active attacks, particularly targeting cryptocurrency assets.

 

Key Takeaways

  • Five distinct malware families have been identified that query LLMs like Gemini and Qwen2.5-Coder during execution to modify or create code.

  • A North Korean-linked group, UNC1069, has been observed using AI to probe cryptocurrency wallets and craft sophisticated phishing scripts.

  • Google has taken action by disabling associated accounts and implementing enhanced safeguards to prevent further misuse of its AI models.

 

The Rise of AI-Enabled Malware

Google's latest report highlights a shift in cybercriminal tactics, moving beyond traditional hard-coded malware. The newly identified malware families utilize LLMs in a "just-in-time code creation" approach. This allows them to dynamically generate malicious scripts, obfuscate their code to evade detection by security software, and create malicious functions on demand. This adaptive nature makes the malware significantly harder to detect and mitigate using conventional security tools.

 

Notable Malware Families and Their Tactics

Two prominent examples of this new breed of malware are PROMPTFLUX and PROMPTSTEAL. PROMPTFLUX employs a "Thinking Robot" module that hourly queries Gemini's API to rewrite its VBScript code, aiming to create an evolving, metamorphic script. PROMPTSTEAL, linked to Russia's APT28 group, uses the Qwen model to generate Windows commands on demand, enabling customized operations without pre-programming.

 

North Korean Involvement in Crypto Theft

The report specifically calls out the North Korean threat actor group UNC1069 (also known as Masan). This group has been observed misusing Gemini for cryptocurrency theft campaigns. Their activities include probing for cryptocurrency wallet data, generating scripts to access encrypted storage, and composing multilingual phishing content aimed at crypto exchange employees. These efforts appear to be part of a broader strategy to steal digital assets.

 

Google's Response and Future Implications

In response to these findings, Google has disabled accounts tied to the identified malicious activities and has tightened safeguards around model access. This includes refined prompt filters and increased monitoring of API access. The emergence of AI-powered malware presents a new attack surface, potentially enabling attackers to craft highly credible phishing lures and exfiltration scripts with unprecedented precision. The trend suggests a growing sophistication in cybercrime, with AI tools becoming increasingly integral to malicious operations.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Google Uncovers AI-Powered Malware Families Linked to North Korean Crypto Theft | BlockzHub