MalTerminal: Researchers Find First LLM-Enabled AI Malware in Wild

AI-Powered Malware and Phishing Attacks Signal New Era of Cyber Threats

  • Researchers identified the earliest known Malware incorporating Large Language Model (LLM) technology, called MalTerminal.
  • MalTerminal can use AI to generate Ransomware or create a reverse shell, but there is no evidence it has been widely used.
  • Attackers are now embedding hidden prompts in phishing emails to bypass AI detection and deliver malicious attachments.
  • Cybercriminals use AI-driven web tools to host fake CAPTCHA pages, making phishing attacks harder to detect.
  • Security companies warn that the use of generative AI is rapidly increasing attack sophistication and scale.

A team at SentinelOne SentinelLABS has found what they call the earliest example of malware with built-in Large Language Model (LLM) features. The malware, known as MalTerminal, was studied by researchers and shared at the LABScon 2025 security conference. The tool uses OpenAI‘s GPT-4 to create ransomware or reverse shell code, techniques often used for controlling infected systems.

- Advertisement -

The group explained that MalTerminal included a now-deprecated OpenAI API endpoint, meaning it was likely created before November 2023. There is no evidence this malware has been released widely, so it may only be a test example or a tool for Cybersecurity teams. Some related Python scripts can also create ransomware or reverse shells, and a detection tool named FalconShield uses an LLM to check if code is malicious.

SentinelOne said, “The incorporation of LLMs into malware marks a qualitative shift in adversary tradecraft.” With LLMs able to generate new commands while running, defenders face new challenges in stopping attacks.

The report also highlights a new method where criminals hide prompts in phishing emails to fool AI-based email security. These hidden messages are concealed in email attachments using styles like “display:none” or “color:white” so users do not see them. For example, an email may look like a business invoice but contain instructions to trick AI-based systems into thinking it is safe.

When a recipient opens the attachment, an attack can begin by exploiting a known vulnerability called Follina (CVE-2022-30190) to run extra software, disable Microsoft Defender, and keep itself active. This technique, called LLM Poisoning, uses comments in web code to bypass AI scanners.

- Advertisement -

A new report from Trend Micro shows more social engineering scams since January 2025 using AI-powered Hosting platforms like Lovable, Netlify, and Vercel. These fake sites often show a CAPTCHA page, then redirect users to phishing sites to steal passwords and other information.

According to Trend Micro researchers, “Victims are first shown a CAPTCHA, lowering suspicion, while automated scanners only detect the challenge page, missing the hidden credential-harvesting redirect.” Analysts warn that free and easy-to-use AI platforms are making these attacks cheaper and faster to run than before.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

MSTR Jumps As MSCI Delays Exclusion of Crypto Treasury Firms

MSTR shares rose nearly 6% in after-hours trading after MSCI said it would not...

Tesla Shares Slip After USPTO Blocks Cybercab, Robotaxi Name

Tesla shares dipped after the United States Patent and Trademark Office denied trademark applications...

Elon Musk’s xAI Raises $20B; Valuation Still Undisclosed Now

xAI raised $20 billion in an upsized Series E, surpassing a prior $15 billion...

Riot sells 2,201 BTC for $200M to fund AI data center build.

Riot Platforms sold 2,201 BTC across November and December, raising nearly $200 million in...

Aave v4 and Lido v3 Spark Major DeFi Upgrades, 2026 Outlook!

Major DeFi protocols plan substantive upgrades in early 2026.Aave is preparing a new architecture...
- Advertisement -

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Bitcoin (BTC) $ 92,416.00 1.43%
Ethereum (ETH) $ 3,242.65 0.78%
XRP (XRP) $ 2.26 4.50%
Bittensor (TAO) $ 283.26 5.52%
Polkadot (DOT) $ 2.18 1.08%
Cardano (ADA) $ 0.410139 3.24%
Chainlink (LINK) $ 13.71 0.64%
Hyperliquid (HYPE) $ 27.71 4.51%
Monero (XMR) $ 440.24 0.72%
Hedera (HBAR) $ 0.125701 4.32%
Toncoin (TON) $ 1.87 1.14%