DeFi Daily News
Saturday, March 28, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title Google Threat Report Links AI-powered Malware to DPRK Crypto Theft – Decrypt

Vince Dioquino by Vince Dioquino
November 7, 2025
in Web 3
0 0
0
rewrite this title Google Threat Report Links AI-powered Malware to DPRK Crypto Theft – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

Google identified five malware families that query LLMs to generate or hide malicious code.
A DPRK-linked group called UNC1069 used Gemini to probe wallet data and craft phishing scripts.
Google says it has disabled the accounts and tightened safeguards around model access.

Google has warned that several new malware families now use large language models during execution to modify or generate code, marking a new phase in how state-linked and criminal actors are deploying artificial intelligence in live operations.

In a report released this week, the Google Threat Intelligence Group said it has tracked at least five distinct strains of AI-enabled malware, some of which have already been used in ongoing and active attacks.

The newly-identified malware families “dynamically generate malicious scripts, obfuscate their own code to evade detection,” while also making use of AI models “to create malicious functions on demand,” instead of having those hard-coded into malware packages, the threat intelligence group stated.



Each variant leverages an external model such as Gemini or Qwen2.5-Coder during runtime to generate or obfuscate code, a method GTIG dubbed “just-in-time code creation.”

The technique represents a shift from traditional malware design, where malware logic is typically hard-coded into the binary.

By outsourcing parts of its functionality to an AI model, the malware can continuously make changes to harden itself against systems designed to deter it.

Two of the malware families, PROMPTFLUX and PROMPTSTEAL, demonstrate how attackers are integrating AI models directly into their operations.

GTIG’s technical brief describes how PROMPTFLUX runs a “Thinking Robot” process that calls Gemini’s API every hour to rewrite its own VBScript code, while PROMPTSTEAL, linked to Russia’s APT28 group, uses the Qwen model hosted on Hugging Face to generate Windows commands on demand.

The group also identified activity from a North Korean group known as UNC1069 (Masan) that misused Gemini.

Google’s research unit describes the group as “a North Korean threat actor known to conduct cryptocurrency theft campaigns leveraging social engineering,” with notable use of “language related to computer maintenance and credential harvesting.”

Per Google, the group’s queries to Gemini included instructions for locating wallet application data, generating scripts to access encrypted storage, and composing multilingual phishing content aimed at crypto exchange employees.

These activities, the report added, appeared to be part of a broader attempt to build code capable of stealing digital assets.

Google said it had already disabled the accounts tied to these activities and introduced new safeguards to limit model abuse, including refined prompt filters and tighter monitoring of API access.

The findings could point to a new attack surface where malware queries LLMs at runtime to locate wallet storage, generate bespoke exfiltration scripts, and craft highly credible phishing lures.

Decrypt has approached Google on how the new model could change approaches to threat modeling and attribution, but has yet to receive a response.

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AIPoweredCryptoDecryptDPRKGoogleLinksmalwarereportrewriteTHEFTThreattitle
ShareTweetShare
Previous Post

rewrite this title Graham Gano Bluntly Addresses Playing in Era of Sports Gambling

Next Post

rewrite this title New XRP ETF Just Dropped, But Will Anything Be Different This Time?

Next Post
rewrite this title New XRP ETF Just Dropped, But Will Anything Be Different This Time?

rewrite this title New XRP ETF Just Dropped, But Will Anything Be Different This Time?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

May 21, 2025
President Trump nominates Kevin Warsh for Fed chair, top takeaways from Apple’s big earnings beat

President Trump nominates Kevin Warsh for Fed chair, top takeaways from Apple’s big earnings beat

January 30, 2026
rewrite this title How to Get Top Solana Token Holders – Moralis APIs

rewrite this title How to Get Top Solana Token Holders – Moralis APIs

May 14, 2025
Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

July 16, 2024
BITCOIN BULL RUN Back On! [Why Everything Changes in September for CRYPTO Markets]

BITCOIN BULL RUN Back On! [Why Everything Changes in September for CRYPTO Markets]

August 23, 2024
‘GAME CHANGER’: Legal expert makes bombshell prediction about Trump’s ongoing cases

‘GAME CHANGER’: Legal expert makes bombshell prediction about Trump’s ongoing cases

November 9, 2024
rewrite this title and make it good for SEOSEEM: A New Emerging Market ETF On The Block (NASDAQ:SEEM)

rewrite this title and make it good for SEOSEEM: A New Emerging Market ETF On The Block (NASDAQ:SEEM)

March 24, 2026
rewrite this title ECB Warns Europe “Could Lose Monetary Sovereignty” to Dominant Stablecoins

rewrite this title ECB Warns Europe “Could Lose Monetary Sovereignty” to Dominant Stablecoins

March 24, 2026
rewrite this title Alix Earle Secret ‘wtfisalixdoing’ Project Revealed

rewrite this title Alix Earle Secret ‘wtfisalixdoing’ Project Revealed

March 24, 2026
rewrite this title with good SEO Gate Integrates Polymarket in First for Centralized Exchanges

rewrite this title with good SEO Gate Integrates Polymarket in First for Centralized Exchanges

March 24, 2026
rewrite this title Apple Maps will introduce ads this summer

rewrite this title Apple Maps will introduce ads this summer

March 24, 2026
Daily Market Coverage Mar. 24, 2026 9AM-11AM (ET) | Yahoo Finance

Daily Market Coverage Mar. 24, 2026 9AM-11AM (ET) | Yahoo Finance

March 24, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.