Recent research has demonstrated that large language models (LLMs) such as GPT-3.5-Turbo and GPT-4 can be manipulated into generating malicious code, including scripts designed for defense evasion and anti-virtualization detection. While these models can produce operational malware under certain conditions, the resulting code remains unreliable and ineffective for real-world deployment, as shown by Netskope Threat Labs' experiments. The process often requires prompt engineering to bypass safety guardrails, and even then, the generated malware struggles to function consistently across different environments.
To address the risks posed by AI-generated code, new defensive tools like BlueCodeAgent have been developed to help developers and security engineers identify and mitigate vulnerabilities introduced by LLMs. BlueCodeAgent employs automated red-teaming, adversarial prompt optimization, and sandbox-based testing to detect biased, malicious, or vulnerable code produced by LLMs. According to Microsoft, this tool outperforms baseline methods in identifying a range of code-generation risks, offering a proactive approach to securing software development workflows that leverage AI models.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
A report published on November 20, 2025 said malware produced with large language models is getting better, while noting fully autonomous AI-driven attacks are not expected imminently. This reflects a new assessment of the threat landscape rather than a specific attack incident.
BlueCodeAgent was reported as offering a tool to help developers identify and address security issues in AI-generated code. The reference indicates the product was publicly discussed or announced by November 20, 2025.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.