AI-powered malware is malicious software that uses an AI model, during development or while it runs, to change its own code, write new commands on demand or adapt when it is caught. Hackers use it to evade detection because antivirus that matches known code patterns has nothing stable to match. The good news for small businesses is that the defences that work are mostly familiar ones.
Security researchers at Google, ESET and Anthropic have now documented real examples, some still experimental and some used in live attacks. Below is what each technique actually does, which examples are proven rather than hyped, why older defences struggle, and the steps that still stop these attacks on a small business network or website.
What is AI-powered malware?
Traditional malware ships with its instructions written in. Once a security company has seen a sample, it can write a signature, a kind of fingerprint, and block every copy. AI-powered malware breaks that model in one of two ways: the attacker uses AI to produce many different versions quickly, or the malware itself contacts an AI model and asks it for fresh code or commands each time it runs.
Google's Threat Intelligence Group described the shift in November 2025, reporting that attackers had moved from using AI for technical help to deploying "novel AI-enabled malware in active operations". It is still early. Several of the best-known samples are prototypes, and human attackers still do most of the work. But the direction is documented, not speculative.
How hackers use AI to evade detection
The techniques researchers have found so far fall into six groups:
- Rewriting the malware's own code on a schedule.
- Asking an AI model for commands while the malware runs.
- Rebuilding malware automatically after it is detected.
- Hijacking AI tools already installed on the victim's computer.
- Planting text meant to fool AI-based security tools.
- Writing better phishing and deepfakes to get the malware in.
Real AI-powered malware examples, and how proven they are
| Name | Reported by | What the AI does | Status |
|---|---|---|---|
| PROMPTFLUX | Google (Nov 2025) | Asks Gemini to rewrite its own script to avoid antivirus. | Experimental, no confirmed victims. |
| PROMPTSTEAL (LAMEHUG) | Google (Nov 2025) | Asks an open model for commands to collect and steal documents. | Used in live attacks on Ukraine. |
| PromptLock | ESET (Aug 2025) | Uses a local AI model to write ransomware scripts on the spot. | Academic proof of concept. |
| QUIETVAULT | Google (Nov 2025) | Uses AI tools on the infected machine to hunt for passwords and keys. | Used in live attacks. |
| FRUITSHELL | Google (Nov 2025) | Contains prompts aimed at misleading AI-based security analysis. | Used in live attacks. |
| s1ngularity (Nx package) | Wiz and others (Aug 2025) | Ran developers' own AI coding assistants to search for secrets. | Used in a real supply chain attack. |
1. Rewriting its own code on a schedule
The clearest example of AI used purely for evasion is PROMPTFLUX, found by Google's researchers in 2025. It contains a module that sends its own source code to Google's Gemini model and asks for a rewritten, disguised version. One variant was designed to regenerate itself "on an hourly basis", saving each new copy so it would start again when the computer restarts.
Code that changes shape to avoid signatures is called polymorphic malware, and it is not new. What AI changes is the cost: instead of a skilled author building a mutation engine, the malware simply asks a language model for a new version. Google found PROMPTFLUX was still being tested, with key functions switched off, and disabled the accounts and API keys it used.
2. Asking an AI model for commands while it runs
A second approach leaves the harmful instructions out of the malware entirely. PROMPTSTEAL, which Google links to the Russian military intelligence group APT28, carries plain-English requests instead, such as a prompt asking for commands to copy office and PDF documents. It sends them to an AI model hosted on Hugging Face and runs whatever comes back. Google called it the first malware it had seen querying a language model in live operations.
PromptLock works the same way with ransomware. ESET found that it uses an openly available OpenAI model, running locally, to generate malicious scripts on the fly, so the traces it leaves can differ every time it runs. ESET later confirmed the sample was a university research prototype, not a criminal tool, which is a useful reminder that "first AI ransomware" headlines often describe experiments.
3. Rebuilding malware automatically after it is caught
This is the technique that worries defenders most, because it removes a delay they have always relied on. When a security company spots new malware, it writes a detection and pushes it out, and the attacker has to spend time and skill producing a new version.
Anthropic's September 2026 threat report describes a Russian espionage group that automated that step. According to the report, if the group's AI agents saw that any deployed malware had been detected by a security product, they would modify and rebuild it to evade the detection, then redeploy it. Anthropic's conclusion was that AI "inverted the cost back onto defenders".
4. Hijacking AI tools already on the victim's computer
Some malware no longer needs to bring its own AI. In August 2025, attackers published poisoned versions of Nx, a popular developer tool. The malicious code checked whether the victim had AI coding assistants installed, such as Claude Code or Gemini CLI, and ran them with their permission checks switched off to search the computer for passwords and keys. Wiz reported that the attack leaked over a thousand valid GitHub tokens and dozens of cloud credentials. Google describes a similar credential stealer, QUIETVAULT.
For a small business, the lesson is that AI agents with broad access to files and accounts become one more thing an attacker can borrow. Keep their permissions narrow, and do not let them run unattended on machines that hold client data. Our guide to using AI at work safely covers what should never go into these tools in the first place.
5. Planting text meant to fool AI-based security tools
Security companies increasingly use AI to read suspicious files and decide whether they are harmful. Attackers have noticed. Google reported that FRUITSHELL, a remote access tool used in real attacks, contains hard-coded prompts meant to bypass analysis by AI-powered security systems. This is prompt injection aimed at the defender: text inside the malware that tries to talk an AI analyst into labelling it safe.
It is a good reason not to rely on any single AI verdict, whether from a security product or a chatbot you paste a file into.
6. Writing better phishing and deepfakes to get the malware in
Most malware still needs someone to click a link, open an attachment or approve a payment. AI makes that first step much more convincing.
- Personalised phishing at scale. In a study by researchers including Bruce Schneier, fully AI-automated spear phishing emails were clicked by 54 percent of participants, the same rate as emails written by human experts and far above the 12 percent for generic phishing.
- Deepfake video calls. A finance employee at the engineering firm Arup paid out about $25 million after a video call in which the "colleagues" were deepfakes.
- Cloned voices. The FBI has warned of a campaign using AI-generated voice messages impersonating senior US officials to get targets to click malicious links.
Spelling mistakes and clumsy wording used to be the easiest warning signs. They are no longer reliable.
How dangerous is AI malware right now?
Serious, but narrower than many headlines suggest. Several famous samples are prototypes, and the most advanced cases so far involve state-backed groups. The bigger shift is who can attack. Anthropic's August 2025 report described a criminal with little coding skill who appeared dependent on AI to develop functional malware, then sold ransomware built this way for $400 to $1,200. Its latest report sums up the trend in one line: sophisticated attacks no longer require sophisticated attackers.
The UK's National Cyber Security Centre expects the same. Its 2025 assessment says the time between a vulnerability being disclosed and exploited "has shrunk to days and AI will almost certainly reduce this further", and warns of a divide between systems that keep pace and a large number that stay vulnerable. Small businesses with unpatched software are on the wrong side of that divide.
Why signature-based antivirus struggles against AI malware
Older antivirus works like a list of wanted faces. It compares each file with fingerprints of known malware. That fails when every copy looks different, or when the harmful part is written by an AI model only after the program starts running.
What still works is watching behaviour. Whatever its code looks like, ransomware has to open and encrypt large numbers of files, a data stealer has to read documents and send them somewhere, and a remote access tool has to connect out to its controller. Endpoint detection and response (EDR) tools look for those actions, and AI malware that calls a commercial AI service also creates network traffic that can be spotted and blocked.
How to protect your business from AI-powered malware
None of the examples above needed a new kind of defence. They exploit the same gaps as ordinary malware: unpatched software, stolen passwords, over-trusting staff and too much access. In order of impact for a small business:
- Patch quickly, starting with what attackers already use. Software vulnerabilities are now the most common way into breached organisations in Verizon's 2026 Data Breach Investigations Report. CISA's Known Exploited Vulnerabilities catalogue shows which flaws are being used right now.
- Switch on phishing-resistant multi-factor authentication. Passkeys and security keys cannot be replayed by a fake login page, unlike text-message codes. CISA explains the options in its phishing-resistant MFA fact sheet.
- Use behaviour-based endpoint protection. Choose security software that monitors what programs do, not only what they look like, and keep it on every laptop and server.
- Keep offline, tested backups. A backup that ransomware cannot reach, and that has actually been restored at least once, turns an attack into an inconvenience.
- Verify payments and access requests on a second channel. Any urgent request for money, passwords or remote access gets a call back on a number you already have, however convincing the email, voice or video looks.
- Limit what AI tools and staff accounts can reach. Give people and AI assistants access only to the files and systems they need, and remove old accounts promptly.
- Watch outbound traffic. Unexpected connections from office machines to AI services or unknown servers are worth investigating.
- Train staff with current examples. Show them realistic AI-written phishing and explain voice cloning, rather than relying on "look for spelling mistakes".
What AI-powered malware means for your website
Websites face the same pressure. Automated scanners already hunt for outdated plugins around the clock, which is why most small business sites get hacked, and AI makes it faster to turn a newly published vulnerability into a working exploit. The practical answer is a shorter gap between an update being released and being applied, plus backups and monitoring that catch a problem early. That is the routine work covered by our website maintenance and security plans.
If your developers use AI to write code, the review step matters too. Our article on how AI is changing web development explains why AI-generated code needs a security check before it goes live.
Frequently asked questions
It is malicious software that uses an AI model to change its code, generate commands while it runs or adapt after detection. Examples documented by Google and ESET include PROMPTFLUX, which asks Gemini to rewrite itself, and PROMPTSTEAL, which asks an AI model for data-stealing commands.
Signature-only antivirus often misses it because each copy can look different. Security tools that monitor behaviour, such as mass file encryption, document theft or unusual outbound connections, are much better at catching it, because the malware still has to do those things.
Yes. Google reported PROMPTSTEAL used against targets in Ukraine and other AI-enabled tools in live operations in 2025, and Anthropic reported a group that automatically rebuilt detected malware in 2026. Some well-known samples, including PromptLock, are research prototypes.
Mostly as part of automated, wide attacks rather than one-off targeting. AI lowers the cost and skill needed, so businesses that were not worth an attacker's time before become worth attacking. Unpatched software and weak authentication are the usual ways in.
Often you cannot, and it does not matter. Judge the request, not the writing: unexpected urgency, a new payment detail, a login link or a request to move to another app. Confirm anything like that through a contact method you already trust.
A 30-minute check for this week
Open the admin panel of your email, accounting software and website, and confirm each one has multi-factor authentication switched on. Check that automatic updates are enabled on every office computer, and ask whoever runs your backups when a restore was last tested. Those three answers will tell you more about your exposure to AI-powered malware than any headline will.


