Skip to main content
Mallory
Malware

Morris II

Morris II is a proof-of-concept AI worm first introduced in 2024 and described as the first worm targeting generative AI systems. It targets LLM-powered or AI-powered email assistants and demonstrates how prompt injection can be used as a self-replicating malware mechanism. In the documented scenario, a malicious prompt embedded in an email is ingested by an AI email assistant, including via retrieval-augmented generation data stores, and the assistant then generates additional outbound emails containing the same malicious prompt. The propagated emails can also include sensitive information, demonstrating data theft and cross-user spread.

The malware’s core behavior is self-replication through adversarial prompts rather than conventional executable payloads. It spreads from user to user by embedding copies of malicious instructions into outgoing emails, and reporting cited in the content describes it as traversing the stages associated with promptware or AI-malware kill chains, including persistence and lateral movement through shared AI-connected data sources. The content explicitly associates Morris II with prompt injection risks in generative AI ecosystems and with poisoning of RAG-backed assistant workflows.

High-confidence capabilities described in the content include propagation through AI email workflows, persistence through retrieved content, and exfiltration of sensitive information. The malware is discussed in the context of promptware research and indirect prompt injection, where attacker-controlled instructions are hidden in external content such as emails and later executed by an LLM-based application. No conventional file-based IOC set, hash, or infrastructure indicators are provided in the content. The content does not attribute Morris II to a threat actor; it is described as a research demonstration rather than an in-the-wild campaign. Targeted systems are generative AI applications, specifically AI-powered email assistants and related enterprise or organizational environments that allow LLMs to read, retrieve, and compose email content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.