Skip to content

SecurityIndependently confirmed2 publishers2 min readPublished Updated

405 AI malware samples, 12 sightings: Unit 42's own count argues against an AI defence line item

Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.

The Watch · Security desk

How we use AISend a correction

What happened

  • Unit 42 assembled 405 unique file hashes of malware that touches AI in some way, drawn from WildFire reports, VirusTotal Intelligence and published research.
  • Twelve of the 405 turned up in telemetry from Cortex XDR-protected endpoints in live customer tenants.
  • About 97% of the set exists only in sandboxes and on VirusTotal, with no evidence of reaching a customer endpoint or firewall.
  • Inclusion was deliberately loose: a coin miner with ChatGPT in its filename counted alongside LLM-powered ransomware agents.

Why it matters

  • decision Money moved into AI-specific malware defence comes out of the sandboxing and endpoint analytics that Unit 42 credits with the catches, so the vendor's own data argues against pulling that budget...
  • constraint The prevalence figure is bounded by one vendor's sensor coverage, so it caps how confident anyone can be about scarcity rather than proving it across the industry.
  • contradiction Because branding alone qualified a sample, the twelve production hits may include nothing where AI runs at execution time, which cuts against the alarm and against the study's own precision.
  • precedent A vendor publishing a deflationary count in its own growth category hands buyers a harder question to put to everyone else: production telemetry numbers, not repository totals.

The tells Unit 42 lists are the tells of code written to be read rather than run at a target: configurations aimed at localhost or private address ranges, debug logging left verbose, submission histories showing a single upload from a research organisation or academic institution, and directory paths containing research, mal or analysis [9]. In the proof-of-concept pile sit LLM-powered ransomware frameworks whose hard-coded ransom addresses point at the Bitcoin Genesis Block, which cannot receive a recoverable payment [10]. The whole non-production remainder is sorted into three buckets: proof-of-concept and research code, security validation testing, and AI-themed brand abuse [8].

Subtraction is blunter than the percentage. 393 of the 405 hashes have no sighting on a protected endpoint at all [14]. The twelve that do sit inside an endpoint telemetry window running from December 2024 to June 2025 [5], which works out to fewer than two sightings a month across every non-test Cortex XDR tenant Palo Alto can see [16].

What those twelve did matters more than the fact that there were twelve, because the collection criteria treat a functional agentic loop and a coin miner with ChatGPT in its filename as the same kind of sample [6]. On criteria that inclusive, a production sighting is not by itself evidence of AI doing any work at runtime.

Two things about the source deserve to be held at once. The prevalence measurement is entirely Palo Alto's own: Cortex XDR agent telemetry, plus WildFire sessions forwarded by its firewalls and agents [11]. Absence from that estate is not absence everywhere, and the statement that its products detected and blocked every sample that attempted to reach a customer environment [4] is a vendor marking its own work. Against that, the argument runs away from the vendor's commercial interest in a fresh category. Unit 42 describes the space as overwhelmingly proof-of-concept code, security validation testing and researcher submissions that never reached production [12], and says the AI component does not evade detection, it changes how the code is authored rather than how it executes [1].

That last point is the procurement argument in full. If AI-written malware executes like malware, the things catching it are behavioral detection, cloud-based sandboxing and endpoint analytics [1], which are the same budget lines raided when a parallel AI-specific stack gets bought mid-cycle. Unit 42 still says the threat is real, only that operational volume is a fraction of what public repositories imply [13]. The spending case that survives its own data is better telemetry, the kind that would show the twelve becoming twelve hundred, not a second detection layer bought on the strength of VirusTotal counts.

What to watch

  • Whether Unit 42 breaks out what the twelve production samples actually did at runtime, or whether they were AI in name only.
  • A comparable production count from a vendor with a different sensor estate; a materially higher number would put the 97% figure in dispute.
  • The first incident where an agentic execution loop, rather than LLM-written code, is the reason a behavioral detection missed.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption15
Hype gap+20
Incentives75
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Unit 42 says existing behavioral detection, cloud-based sandboxing and endpoint analytics catch these threats using the same mechanisms that stop conventional malware; the AI component does not evade detection, it changes how the code is authored, not how it executes.

  2. [2]

    Unit 42's starting dataset consisted of 405 unique SHA-256 hashes collected from WildFire analysis reports, VirusTotal Intelligence and published open-source intelligence research.

  3. [3]

    Of the 405 samples, only 12 appeared in Unit 42's telemetry on Cortex XDR-protected endpoints.

Sources

2 independent publishers whose own reporting we read for this story.

  1. securityweek.com

    1 article · August 26, 2026

    AI Speeds Up Malware Development, Not Its Success Rate: Analysis
  2. unit42.paloaltonetworks.com

    1 article · August 25, 2026

    The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories