Skip to content

Bitcoin Theft Linked to AI Malware

Google Identifies AI-Driven Malware Families Targeting Cryptocurrency

  • Google’s Threat Intelligence Group identified five malware families that use large language models (LLMs) to generate or obfuscate malicious code.
  • A North Korean group, UNC1069, used the Gemini model to probe wallet data and create phishing scripts aimed at cryptocurrency exchange employees.
  • Malware families PROMPTFLUX and PROMPTSTEAL integrate AI models for dynamic script generation, with PROMPTSTEAL linked to Russia’s APT28 group using the Qwen model.
  • Google has disabled accounts associated with these activities and implemented new safeguards, including refined prompt filters and tighter API access monitoring.

The use of LLMs in malware marks a significant evolution in cyber threats, allowing attackers to dynamically generate code that adapts to evade detection systems. This development highlights the increasing sophistication of state-linked cyber operations targeting digital assets.

Google’s actions against these AI-driven threats underscore the need for enhanced security measures in protecting cryptocurrency exchanges from evolving cyber risks. (Source)

Share