unit42 · Crawled Sep 1, 2026

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

12 IoCs 1 Actors 2 Malware
Read original article ↗

AI Summary

Unit42 analyzed 405 AI-enabled malware samples and found that only 12 were observed in production environments, indicating that most such malware remains in proof-of-concept or testing stages. The operational threats included FunkSec ransomware, a trojanized AI application (Recipe Lister), the Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. These threats used techniques such as code signing abuse, DLL side-loading, and social engineering leveraging AI branding. All were detected and blocked by existing defenses including sandboxing, behavioral analytics, and cloud-based verdicts, with no novel detection methods required.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 12 extracted

Type Value Detail
SHA-256 1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7 Details →
SHA-256 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd Details →
SHA-256 dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac Details →
SHA-256 66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd Details →
SHA-256 c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c Details →
SHA-256 e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22 Details →
SHA-256 b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb Details →
SHA-256 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d Details →
SHA-256 dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966 Details →
SHA-256 c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14ef Details →
SHA-256 bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7 Details →
SHA-256 4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14 Details →

MITRE ATT&CK TTPs 24 techniques