An Information Security Media Group interview with security researcher Candid Wüest (Xorlab) discussed how generative AI systems (e.g., ChatGPT, Gemini, Claude) can be used to produce malware and ransomware code, but typically include guardrails intended to block overtly malicious requests. Wüest said attackers can still obtain harmful output through prompt “jailbreak” techniques, where the model is asked indirectly or with obfuscation rather than with explicit malware-writing instructions.
The interview highlighted that some attacker-oriented or less-restricted models (e.g., WormGPT) reduce the need for rephrasing, and described a current evasion pattern of requesting malicious content in poetic/rhyming formats (e.g., limericks/sonnets) to coax responses that would otherwise be refused. The content is presented as expert commentary on attacker tradecraft and AI safety limitations rather than reporting a specific breach, vulnerability disclosure, or active campaign.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
In interviews published on February 10, 2026, Wüest said generative AI can help attackers create malware and bypass some guardrails through jailbreaks or stepwise prompting, but does not reliably produce novel, undetectable ransomware. He emphasized that behavior-based defenses still detect actions such as file encryption and warned about enterprise AI copilots creating data leakage and destructive automation risks.
Vendor reporting cited by Wüest said a Chinese nation-state actor used Claude to automate large portions of an intrusion chain. He noted the details were limited and that hallucinations reportedly caused failures and false claims of access.
Following reporting on LameHug in 2025, Candid Wüest said the malware was likely associated with the Russian state-linked threat group APT28. This represented an attribution assessment tied to the AI-assisted malware example.
In 2025, Ukrainian CERT reported LameHug, an early malware example that embedded an LLM prompt and used Qwen 2.5 to generate system-discovery commands. Xorlab's Candid Wüest described the implementation as having little practical variability because of a low temperature setting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.