<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>AI malware · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/ai-malware/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/ai-malware/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on ai malware, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Answer revised: How are attackers using AI agents in real operations?</title>
<link>https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/</link>
<guid isPermaLink="false">answer:how-are-attackers-using-ai-agents:2026-09-26</guid>
<pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
<category>Key question</category>
<description>Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs. (moderate confidence) Correction: the extortion campaign ran under human direction, security vendors are among the sources, and Google has not yet seen fully autonomous pipelines in the wild. Government threat reports are still missing from the corpus.</description>
</item>
<item>
<title>Answer revised: How are attackers using AI agents in real operations?</title>
<link>https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/</link>
<guid isPermaLink="false">answer:how-are-attackers-using-ai-agents:2026-09-25</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Key question</category>
<description>Increasingly to run parts of intrusions: providers report agent-driven espionage, extortion and credential theft, and malware that queries LLMs as it runs. (moderate confidence) Revised after twelve threat-intelligence and malware reports from 2024 to September 2026 (Anthropic, ESET, Google, Microsoft with OpenAI, Sysdig and ThreatDown) were added, closing most of the coverage gap the first answer described.</description>
</item>
<item>
<title>ThreatDown finds Carbonato, a Docker botnet that installs an AI agent to run operators’ tasks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/threatdown-carbonato-agent-botnet-2026/</link>
<guid isPermaLink="false">event:threatdown-carbonato-agent-botnet-2026</guid>
<pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>ThreatDown reports a botnet that compromises Docker hosts with unauthenticated APIs, installs the open-source Hermes Agent framework with a replaced persona file, and has the agent carry out tasks sent over Telegram, including collecting AI API keys and other credentials. ThreatDown recovered the operation's toolchain from an exposed registry, with images dating from October 2024 to August 2026, and describes the agent reading command output and deciding next steps in an operator-driven loop. It shows an off-the-shelf agent framework used as a botnet implant, with AI API keys treated as a primary theft target.</description>
</item>
<item>
<title>Sysdig documents JADEPUFFER, a database-extortion intrusion it says an LLM agent ran end to end</title>
<link>https://agentic-cyber-explorer.pages.dev/events/sysdig-jadepuffer-agentic-ransomware-2026/</link>
<guid isPermaLink="false">event:sysdig-jadepuffer-agentic-ransomware-2026</guid>
<pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Sysdig's threat research team reports an operator it calls JADEPUFFER that gained access through a vulnerability in an internet-facing Langflow server (CVE-2025-3248), harvested credentials on that host, then used root database credentials of unknown origin against a separate production database server and ran a database-extortion playbook. Sysdig assesses the operation was driven end to end by an LLM agent, citing self-narrating payloads with natural-language reasoning and rapid adaptive retries, and calls it the first documented case of agentic ransomware. A security vendor's evidence-based case that an agent, not a human-written script, conducted a full extortion intrusion, though the attribution of autonomy rests on code artifacts.</description>
</item>
<item>
<title>Google Threat Intelligence reports the first criminal zero-day exploit it believes was AI-developed, disrupted before planned mass use</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-developed-zero-day-2026/</link>
<guid isPermaLink="false">event:gtig-ai-developed-zero-day-2026</guid>
<pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group reported that cybercriminals planned a mass-exploitation campaign using a two-factor-authentication bypass in an open-source web administration tool, and assessed with high confidence that an AI model supported discovery and weaponization of the flaw. GTIG worked with the vendor on disclosure and disrupted the activity. The same report describes PRC-nexus actors using agentic frameworks such as Hexstrike and Strix for reconnaissance and vulnerability validation, and Android malware (PROMPTSPY) that calls Gemini to drive the device UI. GTIG calls it the first identified instance of a zero-day exploit it believes was AI-developed by cybercrime actors.</description>
</item>
<item>
<title>VirusTotal finds hundreds of malicious OpenClaw agent skills distributing stealers and backdoors</title>
<link>https://agentic-cyber-explorer.pages.dev/events/virustotal-malicious-openclaw-skills-2026/</link>
<guid isPermaLink="false">event:virustotal-malicious-openclaw-skills-2026</guid>
<pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>VirusTotal analyzed more than 3,016 OpenClaw skill packages and reports hundreds with malicious behavior, including data exfiltration, backdoors, malware droppers such as Atomic Stealer, and persistent instruction files that manipulate the agent. One publisher accounted for 314 malicious skills; VirusTotal added native scanning of skill packages. Agent skill marketplaces became an in-the-wild malware distribution channel within months of launch.</description>
</item>
<item>
<title>Google reports malware that queries LLMs during execution, including APT28's PROMPTSTEAL</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-llm-querying-malware-2025/</link>
<guid isPermaLink="false">event:gtig-ai-threat-tracker-llm-querying-malware-2025</guid>
<pubDate>Wed, 05 Nov 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group's AI Threat Tracker says adversaries moved beyond productivity uses in 2025 and began deploying malware that calls LLMs mid-execution, such as PROMPTFLUX, which asks Gemini to rewrite its own code, and PROMPTSTEAL, which queries a hosted open model for commands. GTIG attributes PROMPTSTEAL to Russia's APT28 in operations against Ukraine, and also reports actors posing as CTF players or researchers to get past safeguards and a maturing underground market for AI tools. It is Google's evidence that malware using models at runtime had reached a state operation, after CERT-UA's earlier report of the same malware, and it replaced Google's own productivity-only picture.</description>
</item>
<item>
<title>Anthropic reports Claude Code used to run a data-extortion campaign against at least 17 organizations</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-threat-report-claude-code-extortion-2025/</link>
<guid isPermaLink="false">event:anthropic-threat-report-claude-code-extortion-2025</guid>
<pubDate>Wed, 27 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic's August 2025 threat intelligence report describes a criminal who used Claude Code to automate reconnaissance, credential harvesting and network intrusion against at least 17 organizations, including healthcare, emergency services, government and religious institutions, then threatened to publish the stolen data. The report also describes North Korean operatives using Claude to obtain and keep remote technical jobs, and a low-skill actor selling ransomware developed with Claude. Anthropic presents it as agentic AI carrying out attacks rather than only advising on them, with a human still directing the operation.</description>
</item>
<item>
<title>s1ngularity: compromised Nx npm packages used local AI coding CLIs to hunt for secrets</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nx-s1ngularity-weaponized-ai-clis-2025/</link>
<guid isPermaLink="false">event:nx-s1ngularity-weaponized-ai-clis-2025</guid>
<pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Attackers exploited a GitHub Actions workflow injection to steal Nx's npm token and publish malicious versions whose install script scanned systems for secrets, attempted to use locally installed AI CLIs such as Claude and Gemini to assist, and uploaded results to public GitHub repositories. Nx reports the packages were live about four hours and has since moved to trusted publishing and mandatory 2FA approval. It is an early documented case of malware invoking a victim's own AI coding agents as reconnaissance tools.</description>
</item>
<item>
<title>ESET finds PromptLock, ransomware that writes its scripts with a local LLM, later tied to a research prototype</title>
<link>https://agentic-cyber-explorer.pages.dev/events/eset-promptlock-ai-ransomware-2025/</link>
<guid isPermaLink="false">event:eset-promptlock-ai-ransomware-2025</guid>
<pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>ESET Research reported PromptLock, ransomware samples uploaded to VirusTotal that use a locally run open-weight model to generate scripts for file discovery, exfiltration and encryption at runtime, and called it the first known AI-powered ransomware. In a September 3, 2025 update, ESET said the authors of an academic study had contacted it and that their research prototype closely resembles the samples, supporting ESET's view that PromptLock was a proof of concept rather than malware used in attacks. What ESET called the first known AI-powered ransomware closely resembled an academic prototype, a caution about how early AI-malware claims are read.</description>
</item>
</channel>
</rss>
