Science1 distinct publisher3 min readPublished
Palo Alto's census says 97% of AI-enabled malware lives only in sandboxes and VirusTotal. The sampling frame and a loose definition explain much of that, and the defensive advice survives anyway.
The Scientist · Science desk

Compiled by The ScientistSomething wrong?How this is made
The sampling frame does a lot of the work here. A dataset assembled from WildFire analysis reports, VirusTotal Intelligence and published open-source research [1] is drawn from the three places proof-of-concept code goes specifically to be seen. Finding that most of it never ran anywhere is close to a property of where you looked.
The arithmetic is still worth having in front of you. 393 of the 405 hashes never showed up in endpoint telemetry [2], which puts the production rate at 2.96% [1]. The endpoint window runs December 2024 to June 2025 [6], seven months, so the twelve observed samples work out to fewer than two a month across a large commercial estate [3].
Then there is the denominator. Unit 42 says it deliberately counted any sample where AI was a functional component, a delivery feature, or merely branding, which pulled in cryptocurrency miners that just had "ChatGPT" in the filename [5]. A miner with a fashionable name sits in the same 405 as an LLM-driven ransomware framework. That choice raises the sandbox-only share, and it means any later count run under the same rules can produce a steep growth curve without a single new capability appearing.
The artefact fingerprints are the most useful part of the report for anyone triaging a scary-looking hash. Unit 42 describes samples configured against localhost or private address ranges, verbose debug logging left switched on, single uploads from research or academic organisations, and directory paths containing terms like research, mal or analysis [11]. The cleanest tell is a ransomware proof of concept whose hard-coded ransom address points at the Bitcoin Genesis Block, which cannot receive recoverable payments [10]. Nobody built that to get paid.
The load-bearing claim is the one about mechanism: existing behavioural detection, cloud sandboxing and endpoint analytics catch these samples the same way they catch conventional malware, because AI changes how the code is authored rather than how it executes [8]. That is falsifiable and it is the thing a defender can test locally. It also means the case for a separate AI-malware detection programme rests on a capability nobody in this dataset demonstrated.
Two limits on the read. Palo Alto reports that its own products detected and blocked every sample that tried to reach a customer environment [4], which is the vendor grading its own coverage, and absence from one vendor's non-test tenants [6] is not absence from the world. And the report is dated August 2026 [12] while its telemetry stops in June 2025 [6][7], a gap of about fourteen months [4]. A census this stale can tell you the visible corpus was mostly research exhaust; it cannot tell you what the last year looked like.
Ranked by verification strength, evidence, and original report placement.
Unit 42's starting dataset consisted of 405 unique SHA-256 hashes collected from WildFire analysis reports, VirusTotal Intelligence and published open-source intelligence research.
Approximately 97% of the samples examined exist only in sandboxes, research repositories and VirusTotal, with no evidence they reached a customer endpoint or traversed a customer firewall.
Collection criteria were intentionally broad, including any sample where AI integration was a functional component, a feature of the delivery mechanism, or part of its branding, capturing everything from LLM-powered ransomware agents to cryptocurrency miners that simply used "ChatGPT" in their filename.
Unit 42 states that existing behavioural detection, cloud-based sandboxing and endpoint analytics catch these threats using the same mechanisms that stop conventional malware, because the AI component changes how the code is authored, not how it executes.
Of the 405 samples, only 12 appeared in telemetry on Cortex XDR-protected endpoints.
Endpoint presence was measured using Cortex XDR agent telemetry from non-test tenants covering December 2024 to June 2025.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Disclosed method, one vendor's telemetry
The report names its collection sources, telemetry systems and measurement windows, which is more methodological disclosure than most threat-narrative content offers. But it is a single publisher reporting on its own products' visibility, the summarising table is not reproducible from the supplied text, no per-category sample counts are given, and no independent dataset corroborates the 12-of-405 result.
Operational footprint is marginal
Measured against real-world presence of AI-enabled malware, the observed footprint is small: 12 of 405 samples on protected endpoints (about 3%), five families, three countries, roughly 1.7 sightings per month across a seven-month window. Adoption is low but non-zero — the category exists in production, just far below repository volumes.
Headline ratio outruns its method
The debunking framing is modestly overstated relative to what the method can support. The 97% figure is partly an artifact of a repository-built sampling frame and a definition loose enough to include cryptominers with 'ChatGPT' in the filename, and absence from one vendor's telemetry is not global absence. The unverifiable 'blocked every sample that reached a customer' claim pushes further in the same direction. The gap is small rather than large because the underlying counts, windows and caveats are disclosed, and the defensive advice holds regardless.
Vendor research that validates its own stack
The publisher sells the detection products whose telemetry defines the study and whose efficacy is the study's conclusion. The post lists Palo Alto products that caught the threats 'out of the box' and routes readers to its incident response team. The direction of interest is visible in the text; it does not make the counts wrong, but it shapes which caveats are foregrounded.
Directionally credible, weakly corroborated
Confidence is moderate: the core direction — that catalogued AI malware is dominated by research and validation artifacts — is supported by transparent method and internally consistent counts. It is held down by single-publisher sourcing, vendor incentive alignment, definitional looseness, a repository-derived frame, and a roughly 14-month lag between the last telemetry and the report's date.
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
product
Palo Alto closes CyberArk, and privileged access becomes a bundle line item1 distinct publisher
build
Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.