Google Identifies Five AI-Powered Malware Variants Targeting Crypto Assets
Google's Threat Intelligence Group has identified at least five new malware variants that use large language models to dynamically generate and conceal malicious code, Decrypt reports. The North Korea-linked hacker group UNC1069 was found using Gemini to probe wallet data and craft phishing scripts aimed at stealing digital assets. The malware employ real-time code creation by calling external AI models such as Gemini or Qwen2.5-Coder to evade conventional security detection. Google has disabled the associated accounts and enhanced security measures for model access.