PALO Alto Networks' Unit 42 analyzed 405 AI-related malware samples, revealing that 97% never targeted real systems, primarily remaining in controlled environments. Only 12 samples were detected on live endpoints, triggering security alerts. The malware fell into three categories: proof-of-concept code, defensive testing by organizations, and dubious AI-labeled payloads. The detected malware included ransomware (FunkSec) and backdoors masquerading as popular software.
The study emphasized that traditional detection methods effectively identified these samples, reflecting AI's role in accelerating malware development rather than enhancing its stealth.