Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions.
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-replicating worm targeting OpenClaw/OpenClaw-like autonomous agent environments, designed to propagate between agents or agent instances.
A self-replicating worm-like attack framework targeting LLM agent ecosystems, propagating by hijacking persistent configurations and spreading to agent peers.
A worm that demonstrated self-replication across LLM agent ecosystems by compromising persistent configurations and spreading between agents.
An experimental agent worm framework demonstrating autonomous propagation of adversarial prompts among cooperating agents in multi-agent systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.