Palo Alto Networks’ Unit 42 team analyzed 405 malware samples related in some way to AI, from ransomware partially written using LLM to installers that simply borrowed the name of a popular AI application.
The researchers found that approximately 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target.
Module 42 cross-referenced file 405 hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert logs generated whenever a sample was actually run. Only 12 hashes appeared on live endpoints, while a slightly larger group (15-20 hashes) appeared in network sandbox traffic. Any one of the 12 samples detected on protected endpoints triggered a security alert.
Samples that never reached production are divided into three groups. The largest is proof-of-concept code created to demonstrate a technique: configured to target only local or private networks, filled with debug output that no real attacker would leave, and uploaded once by a research lab or university.
The second group comes from organizations testing their own defenses against previously reported AI malware that can be identified by multiple uploads of the same file from the same source within a short window. A third group uses AI branding only as bait, dressing up simple payloads as installers for well-known AI products with no actual AI functionality behind them.
The 12 samples that reached live endpoints spanned five malware families in three countries, with no concentration in a particular industry or region.
The most common family was FunkSec, a strain of ransomware that multiple researchers linked using LLM. Internal project file names embedded in the analyzed samples indicated that a programmer was going through multiple names for the same ransomware, a pace that Unit 42 said was more consistent with a rapid managed build than a traditional development cycle.
The single most common sample was an installer posing as a recipe finder app called Recipe Lister. It carried a digital signature and quietly launched a backdoor once it was installed. The file was distributed to more than 50 organizations, generating approximately 6,500 endpoint records and approximately 9,600 alerts. Its signature initially escaped suspicion, but an unusual signer combined with highly packaged file contents led to its detection.
Another type of malware, the Oyster backdoor, presents itself as a Dropbox installer bearing a signature that names Dropbox as the publisher. Unit 42 said attackers are increasingly turning to AI tools to generate this kind of delivery code, making it faster and cheaper to establish an initial foothold.
A separate Windows executable provided the Rhadamanthys info-stealing program with active command-and-control communication that was previously linked to an AI-assisted infection chain.
The fifth sample poses as a component of the Chinese security product 360 Total Security and uses a persistence technique known as COM hijacking. Unit 42 included it in the data set because it appeared in campaigns delivered alongside AI-branded lures, even though the sample’s own behavior was independent of the AI.
Ward 42 said existing defenses caught each sample using the same methods that catch conventional malware: sandbox detonation, behavior-based detection, anomalies in digital signatures, and measurements of how strongly a file is packed or encrypted. None of the AI related samples require a new detection method to be identified and blocked.
The findings point to the ongoing role of AI in malware as a way to speed up how quickly attackers can build and modify their tools, rather than a way to make those tools harder to catch.
Connected: Linux Foundation to manage TRACE, an open standard for AI Runtime Attestation
Connected: Anthropic expands access to Mythos 5 to more defenders, reveals $35M open source fund
Connected: Encrypted prompts bypass AI guardrails in Grok and Gemini