[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgqbCWHaLHkxzJs2TdyRKu6RehrtMT2EQFtULzc6G_G0":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"d7a57681-22b4-4e92-81de-30cef2c66d01","AI Speeds Up Malware Development, Not Its Success Rate: Analysis","ai-speeds-up-malware-development-not-its-success-rate-analysis-23adea","Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek.","Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found that nearly all failed to reach production endpoints. While AI tools may accelerate malware development and variation, existing security defenses effectively detect and block these samples using conventional methods. The analyzed samples included ransomware, backdoors, and information stealers, often disguised as legitimate AI applications or tools.","AI-assisted malware is faster to develop but not more successful at evading detection.","Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app. The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target. Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert records generated whenever a sample actually ran. Only 12 hashes surfaced on live endpoints, while a somewhat larger group (15-20 hashes) appeared in network sandbox traffic. Every one of the 12 samples detected on protected endpoints triggered a security alert. The samples that never reached production fall into three groups. The largest is proof-of-concept code built to demonstrate a technique: configured to target only local or private networks, filled with debug output no real attacker would leave behind, and uploaded once by a research lab or university. A second group comes from organizations testing their own defenses against previously reported AI malware, identifiable by repeated uploads of the same file from the same source in a short window. A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products with no actual AI functionality behind them. The 12 samples that did reach live endpoints spanned five malware families across three countries, with no concentration in any particular industry or region. Advertisement. Scroll to continue reading. The most common family was FunkSec, a ransomware strain that multiple researchers have linked to LLM assistance. Internal project file names embedded in the analyzed samples show a developer cycling through several names for the same ransomware, a pace Unit 42 said is more consistent with prompt-driven generation than a traditional development cycle. The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister. It carried a digital signature and quietly launched a backdoor once installed. The file spread across more than 50 organizations, generating roughly 6,500 endpoint records and about 9,600 alerts. Its signature initially avoided suspicion, but an unusual signer combined with heavily packed file contents led to its detection. Another malware strain, the Oyster backdoor, posed as a Dropbox installer, carrying a signature that listed Dropbox as the publisher. Unit 42 said attackers are increasingly turning to AI tools to generate this kind of delivery code, making it faster and cheaper to establish an initial foothold. A separate Windows executable delivered the Rhadamanthys information stealer with active command-and-control communication, which earlier reporting tied to an AI-assisted infection chain. The fifth sample impersonated a component of the Chinese security product 360 Total Security and used a persistence technique known as COM hijacking. Unit 42 included it in the dataset because it appeared in campaigns delivered alongside AI-branded lures, even though the sample’s own behavior did not depend on AI. Unit 42 said existing defenses caught every sample using the same methods that catch conventional malware: sandbox detonation, behavior-based detection, anomalies in digital signatures, and measurements of how heavily a file is packed or encrypted. None of the AI-linked samples required a new detection method to be identified and blocked. The findings point to AI’s current role in malware as a way to speed up how quickly attackers can build and vary their tools, not a way to make those tools harder to catch. Related: Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation Related: Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Related: Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs WordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateFirst Malware Built Specifically for Car Head Units Fuels BotnetCISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data Breach Latest News Adobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksThe MFA Identity Trap: When Authentication Creates a False Sense of SecurityChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data BreachCISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationAlice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTrellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.More People On The MoveExpert Insights The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fai-speeds-up-malware-development-not-its-success-rate-analysis\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F11\u002Fmalware.jpeg","2026-08-26T15:23:45+00:00","2026-08-26T16:00:27.448027+00:00",7,[18,21,24],{"name":19,"type":20},"Palo Alto Networks","vendor",{"name":22,"type":23},"Unit 42","product",{"name":25,"type":26},"LLM","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":27,"icon":29,"name":30,"slug":31},null,"Malware","malware",[33,38,43,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":44},{"id":27,"icon":29,"name":30,"slug":31},{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,54,57],{"type":31,"value":52,"context":53},"FunkSec","Ransomware strain linked to LLM assistance.",{"type":31,"value":55,"context":56},"Oyster","Backdoor posing as a Dropbox installer.",{"type":31,"value":58,"context":59},"Rhadamanthys","Information stealer with AI-assisted infection chain."]