Skip to content

AI-Powered / Autonomous Malware

Risk Level Status

AI-powered malware hypothetically uses machine learning to autonomously adapt its behaviour in response to the target environment, generate realistic social engineering content, identify high-value data, and evolve its tactics without human intervention. While fully autonomous AI malware has not been widely observed in the wild, AI tools are already being used to improve individual attack chain components.

MilestoneYearDetails
Concept2000sSelf-adapting malware theory
DeepLocker2018IBM PoC; face-recognition trigger
AI phishing2018IBM: AI outperforms human phishing
WormGPT/FraudGPT2023Commercial LLMs, no guardrails
AI-enhanced phishing2023+Multiple APTs using LLMs
CapabilityDescription
Targeted PhishingLLMs generate personalised emails from OSINT
Vulnerability DiscoveryML scans code/config for unknown vulns
Evasion AdaptationObserves detection → adjusts approach
Target PrioritisationML identifies valuable files/creds
Polymorphic MutationAI generates functionally equivalent variants
Social Engineering BotLLM conducts extended conversations
ToolYearNotes
DeepLocker2018IBM PoC; hidden malware, face-recognition trigger
WormGPT2023Commercial; no safety guardrails
FraudGPT2023Commercial; fraud-focused LLM
AI phishing2023+APTs using LLMs for spear-phishing
FactorAssessment
Current MaturityComponent-level (phishing, vuln discovery)
Fully AutonomousNot yet observed in wild
Barrier to EntryLowering rapidly (open-source LLMs)
Defensive GapSignature-based AV ineffective
  • AI-based defensive tools — Detect novel, adaptive patterns
  • Robust email auth — DMARC, DKIM, SPF + AI phishing detection
  • User training — Specifically on AI-enhanced social engineering
  • Support AI safety research — Detection methods for adversarial AI
  • Assume AI will be used — Defences not reliant on known patterns
  • Behavioural detection — Not signature-based
TechniqueIDAI Enhancement
PhishingT1566LLM-generated personalised content
Vulnerability ScanningT1590ML-assisted discovery
ObfuscationT1027AI-generated polymorphic variants
Social EngineeringT1598LLM-driven conversation