GPT-4-Powered MalTerminal Malware Demonstrates LLM-Embedded Capabilities
Summary
Hide β²
Show βΌ
Cybersecurity researchers have identified MalTerminal, a malware that leverages OpenAI's GPT-4 to generate ransomware code or reverse shells dynamically. This discovery marks the earliest known example of LLM-embedded malware. MalTerminal was presented at the LABScon 2025 security conference and has not been observed in the wild, suggesting it may be a proof-of-concept or red team tool. The malware includes a deprecated OpenAI API endpoint, indicating it was created before November 2023. Accompanying Python scripts and a defensive tool, FalconShield, were also found. The incorporation of LLMs into malware represents a significant shift in adversary tactics, introducing new challenges for defenders. Additionally, threat actors are using LLMs to bypass email security layers by injecting hidden prompts in phishing emails, exploiting AI-powered security scanners. This technique, combined with LLM Poisoning, allows malicious emails to evade detection and execute attack chains.
Timeline
-
20.09.2025 08:48 π° 1 articles Β· β± 1d ago
GPT-4-Powered MalTerminal Malware Discovered
Researchers identified MalTerminal, a malware that uses OpenAI's GPT-4 to generate ransomware code or reverse shells dynamically. This discovery marks the earliest known example of LLM-embedded malware. The malware includes a deprecated OpenAI API endpoint, indicating it was created before November 2023. Accompanying Python scripts and a defensive tool, FalconShield, were also found. Additionally, threat actors are using LLMs to bypass email security layers by injecting hidden prompts in phishing emails, exploiting AI-powered security scanners. This technique, combined with LLM Poisoning, allows malicious emails to evade detection and execute attack chains. The use of AI-powered hosting platforms for phishing attacks has also escalated, with platforms like Lovable, Netlify, and Vercel being exploited to host fake CAPTCHA pages leading to credential-harvesting websites.
Show sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
Information Snippets
-
MalTerminal uses OpenAI's GPT-4 to generate ransomware code or reverse shells dynamically.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
-
The malware includes a deprecated OpenAI API endpoint, suggesting creation before November 2023.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
-
MalTerminal has not been observed in the wild, indicating it may be a proof-of-concept or red team tool.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
-
Accompanying Python scripts and a defensive tool, FalconShield, were found with MalTerminal.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
-
Threat actors are using LLMs to bypass email security layers by injecting hidden prompts in phishing emails.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
-
LLM Poisoning is used to bypass AI analysis tools with specially crafted source code comments.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48
-
AI-powered hosting platforms like Lovable, Netlify, and Vercel are being exploited to host fake CAPTCHA pages leading to phishing websites.
First reported: 20.09.2025 08:48π° 1 source, 1 articleShow sources
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell β thehackernews.com β 20.09.2025 08:48