BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MalTerminal: Researchers Find First LLM-Enabled AI Malware in Wild

AI-Powered Malware and Phishing Attacks Signal New Era of Cyber Threats

  • Researchers identified the earliest known Malware incorporating Large Language Model (LLM) technology, called MalTerminal.
  • MalTerminal can use AI to generate Ransomware or create a reverse shell, but there is no evidence it has been widely used.
  • Attackers are now embedding hidden prompts in phishing emails to bypass AI detection and deliver malicious attachments.
  • Cybercriminals use AI-driven web tools to host fake CAPTCHA pages, making phishing attacks harder to detect.
  • Security companies warn that the use of generative AI is rapidly increasing attack sophistication and scale.

A team at SentinelOne SentinelLABS has found what they call the earliest example of malware with built-in Large Language Model (LLM) features. The malware, known as MalTerminal, was studied by researchers and shared at the LABScon 2025 security conference. The tool uses OpenAI‘s GPT-4 to create ransomware or reverse shell code, techniques often used for controlling infected systems.

- Advertisement -

The group explained that MalTerminal included a now-deprecated OpenAI API endpoint, meaning it was likely created before November 2023. There is no evidence this malware has been released widely, so it may only be a test example or a tool for Cybersecurity teams. Some related Python scripts can also create ransomware or reverse shells, and a detection tool named FalconShield uses an LLM to check if code is malicious.

SentinelOne said, “The incorporation of LLMs into malware marks a qualitative shift in adversary tradecraft.” With LLMs able to generate new commands while running, defenders face new challenges in stopping attacks.

The report also highlights a new method where criminals hide prompts in phishing emails to fool AI-based email security. These hidden messages are concealed in email attachments using styles like “display:none” or “color:white” so users do not see them. For example, an email may look like a business invoice but contain instructions to trick AI-based systems into thinking it is safe.

When a recipient opens the attachment, an attack can begin by exploiting a known vulnerability called Follina (CVE-2022-30190) to run extra software, disable Microsoft Defender, and keep itself active. This technique, called LLM Poisoning, uses comments in web code to bypass AI scanners.

- Advertisement -

A new report from Trend Micro shows more social engineering scams since January 2025 using AI-powered Hosting platforms like Lovable, Netlify, and Vercel. These fake sites often show a CAPTCHA page, then redirect users to phishing sites to steal passwords and other information.

According to Trend Micro researchers, “Victims are first shown a CAPTCHA, lowering suspicion, while automated scanners only detect the challenge page, missing the hidden credential-harvesting redirect.” Analysts warn that free and easy-to-use AI platforms are making these attacks cheaper and faster to run than before.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tether funds Drift hack victims in swap for USDT adoption

Tether will donate $127.5 million to help Solana-based exchange Drift Protocol recover $286 million...

Russia-linked crypto exchange Grinex shuts down after $13M hack

The sanctioned Russia-linked crypto exchange Grinex has halted operations after a major hack resulted...

Hayes: U.S.-Iran Conflict May Tank Bitcoin Before Liquidity Surge

Arthur Hayes described markets as being in a 'no trade zone' due to geopolitical...

Justin Sun decries “tyranny” in Trump-linked WLFI vote

World Liberty Financial proposed burning 4.5 billion WLFI tokens and restructuring vesting for 62...

Crypto Market-Maker Deal Disclosures Virtually Absent

Market-making arrangements are disclosed by fewer than 1% of crypto protocols, a rate dramatically...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading