How AI-Driven Polymorphic Malware Challenges Signature-Based Detection

Summary
The article explains how LLM-assisted malware such as PROMPTFLUX can generate changing variants that undermine signature matching, and promotes Morphisec’s memory-morphing AMTD approach as a prevention layer.
Key points
- The article describes PROMPTFLUX as an experimental dropper that queries Gemini about hourly to regenerate obfuscated versions; it says researchers observed more than 70 variants in under four hours.
- It also cites PROMPTSTEAL, which uses a model to generate Windows commands for document harvesting, and names PromptLock and BlackMamba as examples of LLM-assisted payload rewriting.
- Frequently changing code can undermine hash- and signature-based detection by reducing the value of stable file fingerprints.
- Morphisec says its Automated Moving Target Defense (AMTD) changes the runtime memory layout and places decoys where malware expects legitimate resources, aiming to stop payloads at execution.
- The article presents AMTD as a complement to EDR, next-generation antivirus, and scanning tools, rather than a replacement.
Article Details
- Topic
- AI-powered polymorphic malware and prevention at execution
MITRE ATT&CK
Malware
BlackMambaNamed families such as PromptLock and BlackMamba use LLMs to rewrite their payloads in real time.PROMPTFLUXIn late 2025, Google's threat researchers disclosed PROMPTFLUX, an experimental dropper that queries the Gemini API roughly once an hour to regenerate fresh, obfuscated versions of itself.PromptLockNamed families such as PromptLock and BlackMamba use LLMs to rewrite their payloads in real time.PROMPTSTEALA companion sample, PROMPTSTEAL, uses a model to generate one-line Windows commands on demand to harvest documents.
Vendors
Products
Gemini APIIn late 2025, Google's threat researchers disclosed PROMPTFLUX, an experimental dropper that queries the Gemini API roughly once an hour to regenerate fresh, obfuscated versions of itself.Morphisec platformIn practice, deterministic prevention fortifies detection and response: it stops the unknown payload at execution, then feeds high-fidelity, low-noise forensic data back to the Morphisec platform and the broader stack.