DeFi Daily News
Saturday, December 13, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title Google Threat Report Links AI-powered Malware to DPRK Crypto Theft – Decrypt

Vince Dioquino by Vince Dioquino
November 7, 2025
in Web 3
0 0
0
rewrite this title Google Threat Report Links AI-powered Malware to DPRK Crypto Theft – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

Google identified five malware families that query LLMs to generate or hide malicious code.
A DPRK-linked group called UNC1069 used Gemini to probe wallet data and craft phishing scripts.
Google says it has disabled the accounts and tightened safeguards around model access.

Google has warned that several new malware families now use large language models during execution to modify or generate code, marking a new phase in how state-linked and criminal actors are deploying artificial intelligence in live operations.

In a report released this week, the Google Threat Intelligence Group said it has tracked at least five distinct strains of AI-enabled malware, some of which have already been used in ongoing and active attacks.

The newly-identified malware families “dynamically generate malicious scripts, obfuscate their own code to evade detection,” while also making use of AI models “to create malicious functions on demand,” instead of having those hard-coded into malware packages, the threat intelligence group stated.



Each variant leverages an external model such as Gemini or Qwen2.5-Coder during runtime to generate or obfuscate code, a method GTIG dubbed “just-in-time code creation.”

The technique represents a shift from traditional malware design, where malware logic is typically hard-coded into the binary.

By outsourcing parts of its functionality to an AI model, the malware can continuously make changes to harden itself against systems designed to deter it.

Two of the malware families, PROMPTFLUX and PROMPTSTEAL, demonstrate how attackers are integrating AI models directly into their operations.

GTIG’s technical brief describes how PROMPTFLUX runs a “Thinking Robot” process that calls Gemini’s API every hour to rewrite its own VBScript code, while PROMPTSTEAL, linked to Russia’s APT28 group, uses the Qwen model hosted on Hugging Face to generate Windows commands on demand.

The group also identified activity from a North Korean group known as UNC1069 (Masan) that misused Gemini.

Google’s research unit describes the group as “a North Korean threat actor known to conduct cryptocurrency theft campaigns leveraging social engineering,” with notable use of “language related to computer maintenance and credential harvesting.”

Per Google, the group’s queries to Gemini included instructions for locating wallet application data, generating scripts to access encrypted storage, and composing multilingual phishing content aimed at crypto exchange employees.

These activities, the report added, appeared to be part of a broader attempt to build code capable of stealing digital assets.

Google said it had already disabled the accounts tied to these activities and introduced new safeguards to limit model abuse, including refined prompt filters and tighter monitoring of API access.

The findings could point to a new attack surface where malware queries LLMs at runtime to locate wallet storage, generate bespoke exfiltration scripts, and craft highly credible phishing lures.

Decrypt has approached Google on how the new model could change approaches to threat modeling and attribution, but has yet to receive a response.

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AIPoweredCryptoDecryptDPRKGoogleLinksmalwarereportrewriteTHEFTThreattitle
ShareTweetShare
Previous Post

rewrite this title Graham Gano Bluntly Addresses Playing in Era of Sports Gambling

Next Post

rewrite this title New XRP ETF Just Dropped, But Will Anything Be Different This Time?

Next Post
rewrite this title New XRP ETF Just Dropped, But Will Anything Be Different This Time?

rewrite this title New XRP ETF Just Dropped, But Will Anything Be Different This Time?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
New Law Requires Large Retailers in New York State to Install Panic Buttons

New Law Requires Large Retailers in New York State to Install Panic Buttons

September 5, 2024
AI to Boost ‘So Much’ of Human Investing, Bridgewater’s Jensen Says

AI to Boost ‘So Much’ of Human Investing, Bridgewater’s Jensen Says

July 8, 2024
rewrite this title Bitcoin Miner Phoenix Group Posts 4 Million Loss and 54% Revenue Decline in Q1 2025

rewrite this title Bitcoin Miner Phoenix Group Posts $154 Million Loss and 54% Revenue Decline in Q1 2025

May 8, 2025
Lionel Messi and the Clear Feeling of an Approaching Closure

Lionel Messi and the Clear Feeling of an Approaching Closure

July 15, 2024
What Does the AI Boom Really Mean for Humanity? | The Future With Hannah Fry

What Does the AI Boom Really Mean for Humanity? | The Future With Hannah Fry

September 12, 2024
rewrite this title Asics' 'Life Changing' Running Shoe With the 'Perfect Blend' of Cushion and Energy Return Is Now Nearly 40% Off

rewrite this title Asics' 'Life Changing' Running Shoe With the 'Perfect Blend' of Cushion and Energy Return Is Now Nearly 40% Off

January 21, 2025
rewrite this title Use this ASUS Chromebook CM30 as a laptop or a tablet for 52% off

rewrite this title Use this ASUS Chromebook CM30 as a laptop or a tablet for 52% off

December 13, 2025
rewrite this title The Long-Term Node Operator Economics of Ordinals and How Inscribed Satoshis Impact Full-Node Sustainability on the Bitcoin Netw

rewrite this title The Long-Term Node Operator Economics of Ordinals and How Inscribed Satoshis Impact Full-Node Sustainability on the Bitcoin Netw

December 13, 2025
Bitcoin REVERSAL from Red to Green as Crypto Stabilizes

Bitcoin REVERSAL from Red to Green as Crypto Stabilizes

December 13, 2025
rewrite this title Ethereum Trades Near Whales’ Cost Basis For The Fourth Time Since 2021 – Historic Test

rewrite this title Ethereum Trades Near Whales’ Cost Basis For The Fourth Time Since 2021 – Historic Test

December 12, 2025
rewrite this title and make it good for SEOWall Street ends lower; fears of AI bubble and inflation send investors away

rewrite this title and make it good for SEOWall Street ends lower; fears of AI bubble and inflation send investors away

December 12, 2025
rewrite this title USPS Announces Delivery Warnings in 15 States Due to Winter Storms

rewrite this title USPS Announces Delivery Warnings in 15 States Due to Winter Storms

December 12, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.