Most AI-linked malware samples never reach targets

Palo Alto Networks’ Unit 42 analyzed 405 AI-linked malware samples; 97% stayed in testing and only 12 reached live endpoints, all detected by existing security controls.

Palo Alto Networks’ Unit 42 examined 405 malware samples connected to AI in a recent analysis. The team matched file hashes against endpoint telemetry, network sessions sent for sandbox analysis and internal alert logs. About 97% of the samples remained in sandboxes, research repositories or internal testing and did not reach live targets.

Between 15 and 20 hashes appeared in network sandbox traffic. Twelve hashes surfaced on protected endpoints across five malware families in three countries. Each of those 12 triggered an alert in the vendor’s systems.

Unit 42 sorted the nonproduction samples into three groups. The largest group consisted of proof-of-concept code configured to run only on local or private networks and containing debug output. A second group came from organizations repeatedly uploading the same files while testing defenses. The third group used AI branding as bait, packaging ordinary payloads to look like well-known AI applications without any AI functionality.

Among the 12 live detections, the most common family was FunkSec, a ransomware strain linked by researchers to assistance from large language models. Some FunkSec samples contained internal project file names that changed rapidly, a pattern the team linked to prompt-driven generation.

The single most encountered sample posed as a recipe app called Recipe Lister. That installer carried a digital signature, installed a backdoor and spread to more than 50 organizations, producing about 6,500 endpoint records and roughly 9,600 alerts. An unusual signer combined with heavy packing contributed to its detection.

Other live samples included an Oyster backdoor that impersonated a Dropbox installer and listed Dropbox as the publisher in its signature; a Windows executable that delivered the Rhadamanthys information stealer and maintained active command-and-control communications; and a file that mimicked a component of 360 Total Security and used COM hijacking to persist. Unit 42 included the latter because it appeared in campaigns delivered with AI-branded lures even though its behavior did not depend on AI.

Unit 42 reported that existing defenses detected the AI-linked samples with standard techniques: detonating files in sandboxes, behavior-based detection, checks for anomalies in digital signatures and measurements of how heavily files were packed or encrypted. The analysis found no need for new detection methods to identify the samples in this set.

Articles by this author