The Containment Era is here. →Explore

Executive Summary

In November 2025, Google’s threat intelligence team identified a novel malware campaign involving PROMPTFLUX, a Visual Basic Script (VBScript) threat that leverages the Gemini AI model API for rapid self-obfuscation and evasion. Unattributed attackers deployed PROMPTFLUX to rewrite its own source code hourly using AI-driven prompts, significantly complicating detection and dismantling efforts. The malware infiltrated enterprise endpoints using social engineering and malicious email attachments before laterally propagating within corporate environments, thus undermining traditional endpoint and network defense measures. As a result, organizations faced heightened risk of data exfiltration, operational disruption, and increased response complexity.

This incident highlights an emerging class of threats that weaponize generative AI models for polymorphic malware development. The ability to dynamically morph malicious code in real time increases attacker agility and strains legacy detection and compliance controls, reflecting a wider shift toward autonomous, AI-powered cyberattacks.

Why This Matters Now

PROMPTFLUX demonstrates the urgent risk posed by malware that integrates AI APIs to evade security controls and amplify attack speed. As generative AI capabilities expand, security teams must prioritize adaptive controls, anomaly detection, and enhanced east-west security to counteract rapidly evolving threats that leverage autonomous code mutation.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

PROMPTFLUX used Gemini AI to rewrite its VBScript payload hourly, defeating signature-based detection and complicating incident response with polymorphic tactics.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust network segmentation, east-west workload isolation, encrypted traffic controls, egress enforcement, threat detection, and distributed inline policy would have restricted PROMPTFLUX's ability to move, communicate, and exfiltrate data in the cloud. CNSF capabilities would contain lateral movement, block unauthorized command and control, detect anomalies, and enforce least-privilege cloud access for rapid incident response.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Initial inbound connections and malware downloads could be prevented.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevents escalation paths across segments and limits resource access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Restricts unauthorized lateral movement between workloads.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unapproved outbound and dynamic C2 connections.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Detects, inspects, and blocks hidden or encrypted exfiltration flows.

Impact (Mitigations)

Detects polymorphic malware behavior and triggers rapid incident response.

Impact at a Glance

Affected Business Functions

  • IT Security
  • Network Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

No data exposure reported; malware is in experimental phase with no confirmed compromises.

Recommended Actions

  • Enforce zero trust segmentation to tightly isolate workloads and prevent unsanctioned east-west movement.
  • Deploy egress filtering and application-level policy to stop dynamic malware communications and outbound data exfiltration.
  • Enable inline traffic inspection and encrypted flow monitoring to detect and block hidden C2 or exfiltration attempts.
  • Integrate automated anomaly detection to rapidly identify and quarantine workloads showing self-modifying or evasive behavior.
  • Centralize multicloud visibility and distributed policy enforcement to streamline incident response and reduce attacker dwell time.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image