Security1 distinct publisher2 min readPublished
Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The tells Unit 42 lists are the tells of code written to be read rather than run at a target: configurations aimed at localhost or private address ranges, debug logging left verbose, submission histories showing a single upload from a research organisation or academic institution, and directory paths containing research, mal or analysis [9]. In the proof-of-concept pile sit LLM-powered ransomware frameworks whose hard-coded ransom addresses point at the Bitcoin Genesis Block, which cannot receive a recoverable payment [10]. The whole non-production remainder is sorted into three buckets: proof-of-concept and research code, security validation testing, and AI-themed brand abuse [8].
Subtraction is blunter than the percentage. 393 of the 405 hashes have no sighting on a protected endpoint at all [11]. The twelve that do sit inside an endpoint telemetry window running from December 2024 to June 2025 [4], which works out to fewer than two sightings a month across every non-test Cortex XDR tenant Palo Alto can see [12].
What those twelve did matters more than the fact that there were twelve, because the collection criteria treat a functional agentic loop and a coin miner with ChatGPT in its filename as the same kind of sample [5]. On criteria that inclusive, a production sighting is not by itself evidence of AI doing any work at runtime.
Two things about the source deserve to be held at once. The prevalence measurement is entirely Palo Alto's own: Cortex XDR agent telemetry, plus WildFire sessions forwarded by its firewalls and agents [13]. Absence from that estate is not absence everywhere, and the statement that its products detected and blocked every sample that attempted to reach a customer environment [3] is a vendor marking its own work. Against that, the argument runs away from the vendor's commercial interest in a fresh category. Unit 42 describes the space as overwhelmingly proof-of-concept code, security validation testing and researcher submissions that never reached production [14], and says the AI component does not evade detection, it changes how the code is authored rather than how it executes [6].
That last point is the procurement argument in full. If AI-written malware executes like malware, the things catching it are behavioral detection, cloud-based sandboxing and endpoint analytics [6], which are the same budget lines raided when a parallel AI-specific stack gets bought mid-cycle. Unit 42 still says the threat is real, only that operational volume is a fraction of what public repositories imply [16]. The spending case that survives its own data is better telemetry, the kind that would show the twelve becoming twelve hundred, not a second detection layer bought on the strength of VirusTotal counts.
Ranked by verification strength, evidence, and original report placement.
Of the 405 samples, only 12 appeared in Unit 42's telemetry on Cortex XDR-protected endpoints.
Approximately 97% of the samples Unit 42 examined exist only in sandboxes and on VirusTotal, with no evidence they reached a customer endpoint or traversed a customer firewall.
Unit 42's starting dataset consisted of 405 unique SHA-256 hashes collected from WildFire analysis reports, VirusTotal Intelligence and published open-source intelligence research.
Palo Alto Networks says its products detected and blocked every sample that attempted to reach a customer environment.
Endpoint presence was measured using Cortex XDR agent telemetry from non-test tenants for December 2024 to June 2025; network visibility used WildFire session data from June 2024 to June 2025.
Collection criteria were broad: any sample where AI integration was a functional component, a feature of the delivery mechanism, or part of its branding, which captured everything from LLM-powered ransomware agents to cryptocurrency miners that simply used ChatGPT in their filename.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quantified but single-vendor and self-measured
The numbers are specific, methodologically described and reproducible in form: 405 hashes, four named telemetry sources, explicit date windows, 12 endpoint sightings, five families, three countries. But every measurement comes from the publisher's own estate and no independent dataset in the supplied material tests the 97% figure, so the evidence is detailed rather than corroborated.
Thin operational footprint
Adoption here is the real-world operational use of AI-linked malware, and the disclosed footprint is small: 12 of 405 samples on protected endpoints over seven months, five families in three countries, with 393 hashes never observed and the remainder confined to sandboxes and VirusTotal. Non-zero and real, but far below repository volume.
Mildly overstated generalisation
The story's direction is deflationary and matches its own data, so the gap is small. It skews slightly positive because a single vendor's telemetry is presented as a general statement about the AI-malware space, the inclusive criteria inflate the denominator with filename-only brand abuse, and the strongest operational claim — that every customer-bound sample was blocked — is unverifiable outside the vendor.
Vendor research with direct product interest
The publisher is the threat-intelligence arm of the security vendor whose telemetry supplies the data, and the post names its own products as having detected the threats out of the box, links to its incident-response service, and concludes that controls customers already run are sufficient. That commercial alignment is visible on the face of the piece and is not disclosed as a limitation.
Internally solid, externally untested
Confidence is moderate: the claims are consistent, numerically specific and methodologically described, and the derived ratios follow arithmetically from the stated counts. It is held down by the single-source cluster, the vendor's direct interest in the conclusion, unquantified visibility gaps outside its telemetry, and a partially truncated results table in the available text.
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
product
Palo Alto closes CyberArk, and privileged access becomes a bundle line item1 distinct publisher
build
Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.