What Unit 42's AI-malware numbers do—and do not—show
Only 12 of 405 samples appeared in Unit 42's endpoint dataset. That is useful evidence, but not a measure of every AI-assisted attack.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
Unit 42 examined 405 AI-related malware samples and found 12 in its production endpoint telemetry. The collection was broad: it included AI-assisted code, AI functionality and files using AI branding. The endpoint observation period ran from December 2024 to June 2025.
That is more limited than saying 97 percent of AI-written malware never reached a victim. Absence from one vendor’s telemetry does not establish absence everywhere, and AI branding does not prove that a model wrote the code.
Separate the questions
There are several different things a business might mean by an “AI attack”. A model could help write a malicious file. An operator could use an assistant to plan or carry out an intrusion. A legitimate agent could be manipulated into misusing its access.
A study of malware files cannot measure all three. It is worth asking which of these a report covers before using its headline to justify a security purchase—or to conclude that nothing needs to change.
Evaluate your existing protection
We recommend reviewing endpoint coverage and response before assuming an AI label demands a new control. Are the machines you depend on reporting? Are exceptions understood? Does somebody investigate the alerts and have authority to contain an incident?
Use an authorised assessment to examine relevant behaviour and the response it produces. Do not assume a result on one vendor’s product applies to another product or to a different configuration.
Also keep the broader question in view: what access do employees and their assistants have? Protecting against a malicious executable does not resolve excessive permissions in an otherwise legitimate tool.
Unit 42 provides a useful dataset, with a defined collection method and observation window. Read it on those terms. The evidence supports a measured assessment, not a universal claim about what AI-enabled attacks can or cannot do.