logo

Analyzing the Current State of AI Use in Malware

ID: 919c224c-c219-5537-a96a-50675953a4b1

STIX ID: report--919c224c-c219-5537-a96a-50675953a4b1

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2026-03-19

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 analyzed two malware samples demonstrating current AI integration trends in malware: a ConfuserEx-obfuscated .NET infostealer that calls OpenAI GPT-3.5-Turbo for logging/naïve evasion and obfuscation suggestions (largely unimplemented ‘‘AI theater’’), and a dropper that sends host telemetry to GPT-4 to gate execution of a Sliver payload. The report details four LLM-invoking functions, sample behaviors (data collection, exfiltration, opsec logging), provides SHA256 IOCs, and assesses implications of AI-assisted decision-making for future malware evolution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.