SecurityIndependently confirmed2 publishers2 min readPublished Updated
405 AI malware samples, 12 sightings: Unit 42's own count argues against an AI defence line item
Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.
The Watch · Security desk
What happened
- Unit 42 assembled 405 unique file hashes of malware that touches AI in some way, drawn from WildFire reports, VirusTotal Intelligence and published research.
- Twelve of the 405 turned up in telemetry from Cortex XDR-protected endpoints in live customer tenants.
- About 97% of the set exists only in sandboxes and on VirusTotal, with no evidence of reaching a customer endpoint or firewall.
- Inclusion was deliberately loose: a coin miner with ChatGPT in its filename counted alongside LLM-powered ransomware agents.
Why it matters
- decision Money moved into AI-specific malware defence comes out of the sandboxing and endpoint analytics that Unit 42 credits with the catches, so the vendor's own data argues against pulling that budget...
- constraint The prevalence figure is bounded by one vendor's sensor coverage, so it caps how confident anyone can be about scarcity rather than proving it across the industry.
- contradiction Because branding alone qualified a sample, the twelve production hits may include nothing where AI runs at execution time, which cuts against the alarm and against the study's own precision.
- precedent A vendor publishing a deflationary count in its own growth category hands buyers a harder question to put to everyone else: production telemetry numbers, not repository totals.
The tells Unit 42 lists are the tells of code written to be read rather than run at a target: configurations aimed at localhost or private address ranges, debug logging left verbose, submission histories showing a single upload from a research organisation or academic institution, and directory paths containing research, mal or analysis [9]. In the proof-of-concept pile sit LLM-powered ransomware frameworks whose hard-coded ransom addresses point at the Bitcoin Genesis Block, which cannot receive a recoverable payment [10]. The whole non-production remainder is sorted into three buckets: proof-of-concept and research code, security validation testing, and AI-themed brand abuse [8].
Subtraction is blunter than the percentage. 393 of the 405 hashes have no sighting on a protected endpoint at all [14]. The twelve that do sit inside an endpoint telemetry window running from December 2024 to June 2025 [5], which works out to fewer than two sightings a month across every non-test Cortex XDR tenant Palo Alto can see [16].
What those twelve did matters more than the fact that there were twelve, because the collection criteria treat a functional agentic loop and a coin miner with ChatGPT in its filename as the same kind of sample [6]. On criteria that inclusive, a production sighting is not by itself evidence of AI doing any work at runtime.
Two things about the source deserve to be held at once. The prevalence measurement is entirely Palo Alto's own: Cortex XDR agent telemetry, plus WildFire sessions forwarded by its firewalls and agents [11]. Absence from that estate is not absence everywhere, and the statement that its products detected and blocked every sample that attempted to reach a customer environment [4] is a vendor marking its own work. Against that, the argument runs away from the vendor's commercial interest in a fresh category. Unit 42 describes the space as overwhelmingly proof-of-concept code, security validation testing and researcher submissions that never reached production [12], and says the AI component does not evade detection, it changes how the code is authored rather than how it executes [1].
That last point is the procurement argument in full. If AI-written malware executes like malware, the things catching it are behavioral detection, cloud-based sandboxing and endpoint analytics [1], which are the same budget lines raided when a parallel AI-specific stack gets bought mid-cycle. Unit 42 still says the threat is real, only that operational volume is a fraction of what public repositories imply [13]. The spending case that survives its own data is better telemetry, the kind that would show the twelve becoming twelve hundred, not a second detection layer bought on the strength of VirusTotal counts.
What to watch
- Whether Unit 42 breaks out what the twelve production samples actually did at runtime, or whether they were AI in name only.
- A comparable production count from a vendor with a different sensor estate; a materially higher number would put the 97% figure in dispute.
- The first incident where an agentic execution loop, rather than LLM-written code, is the reason a behavioral detection missed.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption15
- Hype gap+20
- Incentives75
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Unit 42 says existing behavioral detection, cloud-based sandboxing and endpoint analytics catch these threats using the same mechanisms that stop conventional malware; the AI component does not evade detection, it changes how the code is authored, not how it executes.
- [2]
Unit 42's starting dataset consisted of 405 unique SHA-256 hashes collected from WildFire analysis reports, VirusTotal Intelligence and published open-source intelligence research.
- [3]
Of the 405 samples, only 12 appeared in Unit 42's telemetry on Cortex XDR-protected endpoints.
- [4]
Palo Alto Networks says its products detected and blocked every sample that attempted to reach a customer environment.
ReportedSupportedSource: Unit 42 / Palo Alto Networks2 sources— create a free account to open themView cited source - [5]
Endpoint presence was measured using Cortex XDR agent telemetry from non-test tenants for December 2024 to June 2025; network visibility used WildFire session data from June 2024 to June 2025.
- [6]
Collection criteria were broad: any sample where AI integration was a functional component, a feature of the delivery mechanism, or part of its branding, which captured everything from LLM-powered ransomware agents to cryptocurrency miners that simply used ChatGPT in their filename.
- [7]
Approximately 97% of the samples Unit 42 examined exist only in sandboxes and on VirusTotal, with no evidence they reached a customer endpoint or traversed a customer firewall.
- [8]
Samples that never appeared in production telemetry fall into three categories: proof-of-concept and research code, security validation and testing, and AI-themed brand abuse.
- [9]
Many non-production samples target localhost or private IP ranges, contain verbose debug logging, show a single upload from a security research organisation or academic institution, and were found in file paths containing terms such as research, mal or analysis.
- [10]
Proof-of-concept examples include LLM-powered ransomware frameworks with hard-coded test parameters, such as ransom addresses pointing to the Bitcoin Genesis Block, which cannot receive recoverable payments.
- [11]
Real-world prevalence was queried across Palo Alto's own telemetry: Cortex XDR agent telemetry, WildFire session data from samples forwarded by Next-Generation Firewalls and Cortex XDR agents, Cortex XDR alert records and WildFire sandbox verdicts.
- [12]
Unit 42's central finding was that the AI malware space is currently overwhelmingly composed of proof-of-concept code, security validation testing and researcher submissions that have never reached a production environment.
- [13]
Unit 42 states that AI-enabled malware is real, but the volume of genuine operational activity remains a fraction of what public sample repositories suggest.
- [14]
393 of the 405 collected hashes had no sighting on a Cortex XDR-protected endpoint.
- [15]
The production sighting rate across the dataset is about 3%.
- [16]
Twelve endpoint sightings across the December 2024 to June 2025 window is about 1.7 sightings per month.
Sources
2 independent publishers whose own reporting we read for this story.
- securityweek.comAI Speeds Up Malware Development, Not Its Success Rate: Analysis
1 article · August 26, 2026
- unit42.paloaltonetworks.comThe State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Threat Intelligence and Incident ResponseFollow
- Malware detectionFollow
- AI-enabled malwareFollow
Entities
- Oyster backdoorFollow
- Palo Alto NetworksFollow
- VirusTotalFollow
- Cortex XDR and XSIAMFollow
- Rhadamanthys stealerFollow
- WildFireFollow
- Unit 42Follow
- FunkSecFollow