Emerging Threats
Part IV — Hypothesised & Emerging Malware
Section titled “Part IV — Hypothesised & Emerging Malware”The malware types in this section represent theoretical concepts, early-stage observed threats, or categories that exist in limited forms but represent significant future risks.
Risk: 🔴 Critical | Status: Emerging
AI-powered malware hypothetically uses machine learning to autonomously adapt its behaviour, generate realistic social engineering content, identify high-value data, and evolve tactics without human intervention.
Key Capabilities: Targeted phishing, vulnerability discovery, evasion adaptation, target prioritisation, polymorphic mutation, social engineering automation
Notable: DeepLocker (2018, IBM PoC), WormGPT (2023), FraudGPT (2023)
Risk: 🟠 High | Status: Theoretical
Malware leveraging quantum computing to break current cryptographic protections (RSA, ECC). Adversaries already conduct “harvest now, decrypt later” campaigns.
Key Threat: Shor’s algorithm breaks RSA/ECC; Grover’s reduces AES-256 to 128-bit security
Mitigation: NIST PQC (Kyber, Dilithium, FALCON, SPHINCS+), crypto-agility, hybrid cryptography
Risk: 🔴 Critical | Status: In-the-wild
Firmware malware infects UEFI/BIOS, HDD/SSD controllers, NIC, USB controllers. Executes before OS loads, survives OS reinstallation and disk formatting.
Notable: NSA ANT Catalogue (IRATEMONK, DEITYBOUNCE), LoJax (2018), MosaicRegressor (2020), BadUSB (2014), CosmicStrand (2022), MoonBounce (2022), BlackLotus (2023)
Risk: 🔴 Critical | Status: In-the-wild
Malware compromising software/hardware during development, build, distribution, or update — infecting thousands of downstream customers simultaneously.
Notable: SolarWinds/SUNBURST (2020), XCodeGhost (2015), CCleaner (2017), Event-Stream npm (2018), Codecov (2021), XZ Utils Backdoor (2024)
Risk: 🔴 Critical | Status: In-the-wild
Malware targeting Operational Technology, Industrial Control Systems, SCADA, PLCs — controlling physical processes with potential for destruction and loss of life.
Notable: Stuxnet (2010), BlackEnergy (2015), Industroyer (2016), TRITON/TRISIS (2017), INCONTROLLER (2022)
Risk: 🟠 High | Status: In-the-wild
Polymorphic malware changes its code signature on each replication. Metamorphic malware rewrites its entire code structure while maintaining functionality.
Notable: 1260 Virus (1990), DAME (1992), W32/Simile (2002), Virut (2006), Sality (2003+)