For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/ai-malware-97-percent-never-left-the-sandbox.md.
AI Security ↗

97 percent of AI-written malware never left the sandbox

Unit 42 traced 405 AI-enabled malware samples. Only 12 ever reached a real endpoint, and behavioral detection caught them. Our read for Norwegian SMBs.

Someone finally counted. Palo Alto Networks’ Unit 42 traced 405 malware samples where AI played a part, and only 12 of them ever reached a real, protected endpoint.

The numbers come from a report Unit 42 published on August 25. The researchers collected every sample they could find where AI served as a component, a delivery trick, or just a name, drawing on sandbox reports, VirusTotal, and public research. Then they checked endpoint telemetry to see which samples ever turned up on production machines. About 97 percent never did. They exist in sandboxes and on VirusTotal, and nowhere else.

What the 97 percent is made of

Most of it was never aimed at a victim. Unit 42 sorted the non-production samples into three piles. Proof-of-concept and research code, some with test parameters still hard-coded. Files uploaded again and again by security teams testing their own controls. And conventional malware dressed up with an AI name to ride the wave, what the report calls brand abuse, where “AI” in a filename is the lure and no AI exists inside.

The 12 samples that reached real machines came from five families. Seven were FunkSec ransomware variants, written in Rust and compiled across six days in January 2025. Unit 42 reads that build pace as a sign of LLM-assisted development: the model shortens the time between variants. The widest spread belonged to Recipe Lister, a trojanized AI-branded app that reached over 50 organizations. It carried a valid code signature, and per the report it was still caught, because an uncommon signer and a near-maximum entropy reading tripped behavioral analytics before the sandbox verdict closed the case.

One line in the report carries the whole finding: “None of the AI-enabled samples in our dataset required a novel detection approach.” AI changed how the malware was written. It did not change what the malware does on a machine, and behavior is what modern endpoint detection watches.

A snapshot, not an all-clear

Two weeks ago I wrote that AI-driven hacking is about to scale as open models close the capability gap. This report does not contradict that. It dates it. Unit 42’s endpoint telemetry ends in June 2025, before the current model generation, and the same week the report landed, five US agencies warned that AI-generated scripts are probing industrial controllers. Capability keeps rising. The endpoint numbers have not caught up with the headlines yet, and that gap is the useful information.

Our read for a Norwegian SMB is reassuringly boring. The controls that catch human-written malware catch machine-written malware too, for now. Keep behavioral endpoint detection on every machine, detonate incoming files in a sandbox, and be skeptical of any pitch built on the claim that your current EDR cannot see AI malware. Unit 42’s data says the opposite: every AI-enabled sample that reached a defended endpoint was detected on its behavior, not its author.

Where I would spend attention instead is speed. Seven ransomware builds in six days means the window between variants is shrinking, so signature-based tools fall further behind while behavior-based tools stay level. If your endpoint protection still depends on signatures, this report is your argument for changing that before the 3 percent grows.

Talk to Fredrik Standahl if you want our read on what AI-written malware means for your endpoint coverage.


Drafted with AI assistance, reviewed and edited by Fredrik Standahl and the FM CyberSecurity editorial team.

Sources

  • Unit 42, Palo Alto Networks, “The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution,” August 25, 2026
  • CISA, NSA, FBI, DOE, EPA, “Defending Against an Active Threat to Siemens S7 Series PLCs,” advisory AA26-231A, August 20, 2026
← Back to all insights
Questions or inquiry? [email protected] Contact us →