unit42 · Crawled Sep 1, 2026
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
12 IoCs 1 Actors 2 Malware
Read original article ↗
AI Summary
Unit42 analyzed 405 AI-enabled malware samples and found that only 12 were observed in production environments, indicating that most such malware remains in proof-of-concept or testing stages. The operational threats included FunkSec ransomware, a trojanized AI application (Recipe Lister), the Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. These threats used techniques such as code signing abuse, DLL side-loading, and social engineering leveraging AI branding. All were detected and blocked by existing defenses including sandboxing, behavioral analytics, and cloud-based verdicts, with no novel detection methods required.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7 | Details → |
| SHA-256 | 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd | Details → |
| SHA-256 | dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac | Details → |
| SHA-256 | 66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd | Details → |
| SHA-256 | c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c | Details → |
| SHA-256 | e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22 | Details → |
| SHA-256 | b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb | Details → |
| SHA-256 | 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d | Details → |
| SHA-256 | dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966 | Details → |
| SHA-256 | c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14ef | Details → |
| SHA-256 | bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7 | Details → |
| SHA-256 | 4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14 | Details → |
MITRE ATT&CK TTPs 24 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1071 Application Layer Protocol · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1204 User Execution · Execution T1486 Data Encrypted for Impact · Impact T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1203 Exploitation for Client Execution · Execution T1212 Exploitation for Credential Access · Credential Access T1484.001 Group Policy Modification · Defense Evasion T1542.001 System Firmware · Persistence T1543.003 Windows Service · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1552.001 Credentials In Files · Credential Access T1566 Phishing · Initial Access T1574.002 DLL Side-Loading · Persistence T1588.001 Malware · Resource Development