Malware discovered in late 2025 now checks in with an AI model every hour to generate a new version of itself, according to a report published by The Hacker News in August 2026. Google's Threat Intelligence Group identified the malware, called PROMPTFLUX, which morphs its appearance each time it runs, evading detection by the time security systems learn to recognize it. The report warns that legacy SIEM platforms, built to spot known patterns, are increasingly unable to keep pace with attacks that change shape faster than defenses can adapt.
The report cites IBM's 2026 X-Force Threat Intelligence Index, which found attackers now use AI to conduct research, scan for vulnerabilities, and rewrite phishing emails and malware instantly. The number of active ransomware groups jumped 49% in a single year, driven largely by smaller, short-lived operators entering the field. IBM's 2025 Cost of a Data Breach report found that companies take an average of 241 days to identify and contain a breach, though organizations using AI and automation in security operations cut response time by 80 days and save nearly $1.9 million per breach compared to those that don't.
The report explains that AI has lowered the barrier to entry for attackers, who now reuse leaked tools and rely on AI to automate tasks that once required technical skill, like researching targets or writing convincing lures. According to the analysis, legacy SIEM systems ask "Does this match something bad I've seen before?" while AI-native SIEM platforms ask "Does this look normal for this person, this device, this network?" That shift allows newer systems to flag unusual behavior immediately, even when the exact attack has never been seen before, while older rule-based tools struggle until someone writes a new detection rule.
The report argues that attackers can rewrite malware code every hour, but they can't easily change what the malware must do once inside a network—it still has to search files, locate valuable data, move between computers, and transmit information out. Those actions leave behavioral trails that AI-native systems can detect by learning what normal activity looks like for each user and device, then connecting small anomalies into a single flagged case. This behavior-first approach reduces the need for constant rule updates and groups related signals together, ranking them by severity instead of flooding analysts with thousands of alerts daily.
The report concludes that as AI continues reshaping the threat landscape, the focus is shifting toward identifying meaningful signals sooner and giving analysts the context they need to investigate with confidence. Security teams now spend less time asking whether they've seen an exact threat before and more time evaluating whether an anomaly deserves closer investigation and what else it connects to. The bottom line: attackers who change their face every time they show up can't be stopped by a guard who only memorizes faces.

