YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0033

Incident record

Four hundred AI-enabled malware samples, twelve of them on anyone's machine

Severity
Medium
Status
In the wild
Type
Poisoning
Target
Windows endpoints reached by trojanised AI applications and AI-assisted malware families
Actor
criminal

What happened

Palo Alto Networks Unit 42 collected and analysed more than 400 malware samples that integrate AI in some capacity, and found only 12 of them in its own telemetry on endpoints running its Cortex XDR product, across three countries. Almost everything circulating as AI-enabled malware sits in sandboxes and repositories rather than on a victim's machine.

The 12 fall into five families: seven variants of FunkSec ransomware, a trojanised AI application called Recipe Lister that reached more than 50 organisations, the Oyster backdoor, the Rhadamanthys stealer, and a COM hijacking DLL. Unit 42's own counts, 405 samples analysed against 12 seen in the field, leave roughly 97 per cent of the category sitting outside real-world deployment. Against a year of capability demonstrations, the supply of AI-enabled malware is real and the deployment of it, so far, is thin.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026