Palo Alto Networks' Unit 42 reviewed 405 malware samples that incorporated AI and found that the vast majority were not active threats but proof-of-concept code, security testing artifacts, or malware merely branded around AI themes. Only 12 samples—about 3% of the dataset—were observed on Cortex XDR-protected endpoints, and WildFire session data showed only roughly 15 to 20 unique hashes, indicating that about 97% of the samples remained confined to repositories, sandboxes, or validation environments rather than real-world operations.
The operational activity that was observed mapped to five malware families: FunkSec ransomware, a trojanized AI-themed application, the Oyster backdoor, the Rhadamanthys stealer, and a COM hijacking DLL. Unit 42 said existing defenses, including behavioral analytics, sandboxing, code-signing anomaly detection, and entropy analysis, detected and blocked all observed samples, concluding that AI is currently being used more to speed malware development and strengthen social-engineering lures than to introduce fundamentally new runtime behavior or broadly successful evasion techniques.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
An NSIS installer posing as the Recipe Lister application was the most widely encountered sample, appearing across more than 50 organizations and generating over 6,500 endpoint profile records and 9,600 XDR alerts during the observation window. Palo Alto said Cortex XDR blocked it through local analysis, behavioral protection, and WildFire verdicts, and no execution succeeded on a protected endpoint.
Using endpoint telemetry from non-test tenants covering December 2024 through June 2025, Palo Alto found only 12 of 405 AI-enabled malware samples on Cortex XDR-protected endpoints, representing 3% prevalence in production. These samples appeared across organizations in three countries and mapped to five malware families.
Seven distinct FunkSec ransomware variants later seen in endpoint telemetry were compiled between January 1 and January 6, 2025. Palo Alto noted the variants shared a Rust codebase and showed iterative development through embedded PDB paths.
Palo Alto Networks queried WildFire session data covering June 2024 through June 2025 and found only about 15 to 20 unique hashes from its 405-sample AI-enabled malware dataset, indicating roughly 4% prevalence in observed traffic.
Palo Alto Networks analyzed 405 malware samples that incorporated AI and concluded that most were proof-of-concept code, testing artifacts, or AI-branded malware rather than operational threats. The company reported that all observed operational samples were detected and blocked by existing controls, with no novel detection approach required.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.