Unit 42: Nearly All AI-Enabled Malware Samples Stay in Labs; FunkSec Reaches Production
Date: 2026-08-25
Tags: malware
Executive Summary
Unit 42 published on 2026-08-25 an analysis of 405 AI-enabled malware samples and found only 12 on Cortex XDR-protected endpoints, about 3 percent, with the rest confined to research repos, BAS testing, and AI-branded conventional malware. The production set spans FunkSec ransomware that Unit 42 assessed as partly LLM-assisted, a trojanized Recipe Lister installer, Oyster/CleanBoost, Rhadamanthys, and a 360Util.dll COM-hijack. Hunt the published SHA-256 values; Unit 42 stated existing sandbox, behavioral, and signing-anomaly detections blocked every sample that reached a customer environment.
Campaign Summary
| Field | Detail |
|---|---|
| Campaign / Malware | Unit 42 AI-enabled malware telemetry study; production families FunkSec, Recipe Lister trojan, Oyster/CleanBoost, Rhadamanthys, 360Util COM hijack |
| Actor / Attribution | Multiple families. FunkSec LLM-assist is assessed by Unit 42 and prior researchers, not a named operator. Confidence medium for LLM authorship of FunkSec, none for a single campaign owner |
| Target | Opportunistic. Unit 42 reported three countries and no sector concentration |
| Vector | AI-themed installers and brand abuse; FunkSec ransomware with Defender tampering and shadow-copy deletion; signed loaders |
| Status | Production samples were blocked on Cortex XDR in the study window. Families remain relevant for hunting |
| First Observed | Telemetry window December 2024 through June 2025; FunkSec variants compiled 2025-01-01 through 2025-01-06 |
Detailed Findings
According to Unit 42, the dataset mixed any sample where AI was a functional component, a delivery feature, or branding, collected from WildFire, VirusTotal Intelligence, and OSINT. Endpoint queries used Cortex XDR non-test tenants from December 2024 through June 2025. WildFire session data ran June 2024 through June 2025.
Unit 42 reported 12 of 405 hashes on production endpoints and roughly 15 to 20 unique hashes in WildFire sessions. About 97 percent never appeared on a customer endpoint or firewall. Unit 42 grouped the non-production majority as proof-of-concept and research code, including ransomware frameworks with Bitcoin Genesis Block ransom addresses, BAS and internal test submissions with repeated same-org uploads, and AI-branded conventional malware whose filenames invoke ChatGPT or similar without AI in the payload.
Of the 12 production samples, Unit 42 named five patterns.
FunkSec: seven Rust variants compiled 2025-01-01 through 2025-01-06, sharing Defender disablement via PowerShell and registry, volume shadow copy deletion, and wallpaper ransom notes. PDB names included Dev.pdb, Funksec.pdb, Darkzone.pdb, and Darkfunk.pdb. Unit 42 stated that seven builds in six days is consistent with LLM-assisted iteration. WildFire classified all seven as malware; Cortex XDR alerted on every executing variant.
Trojanized AI application: an NSIS installer posing as Recipe Lister, signed by Global Tech Allies Ltd., certificate later revoked, dropping a JavaScript backdoor. Unit 42 said this hash produced the most telemetry, more than 50 organizations, more than 6,500 endpoint profile records, and more than 9,600 XDR alerts, with no successful execution on a protected endpoint. Detection used uncommon signer plus near-maximum entropy 0.999970, then WildFire.
Oyster/CleanBoost: a Dropbox-signed-looking installer that is not Dropbox software, dropping an AutoIt loader. Unit 42 stated attackers are using AI tools to speed initial-access loader generation.
Rhadamanthys: a .NET redist.exe that Unit 42 said was part of an AI-enabled infection chain in prior reporting.
COM hijack: 360Util.dll impersonating 360 Total Security, included because it arrived with AI-branded lures.
Unit 42's operational conclusion is that AI changes how these binaries are written, not the behaviors existing controls already catch. The study does not claim AI-enabled malware is fictional; it claims production prevalence is a fraction of public-sample volume.
MITRE ATT&CK Mapping
| Technique | ID | Context |
|---|---|---|
| Data Encrypted for Impact | T1486 | FunkSec encrypts and displays a ransom note; Unit 42 observed seven production variants. |
| Impair Defenses: Disable or Modify Tools | T1562.001 | FunkSec disables Microsoft Defender through PowerShell and registry changes. |
| Inhibit System Recovery | T1490 | FunkSec deletes volume shadow copies. |
| Masquerading | T1036 | Recipe Lister, Dropbox, and 360 Total Security branding hide conventional loaders. |
| Subvert Trust Controls: Code Signing | T1553.002 | Recipe Lister used a later-revoked Global Tech Allies certificate; Oyster used a Dropbox-looking Authenticode identity. |
| Boot or Logon Autostart Execution: Component Object Model Hijacking | T1546.015 | 360Util.dll persists via COM hijacking. |
IOCs
Domains
No domain IOCs published by source
Full URL Paths
No URL IOCs published by source
Splunk Format
"1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7" OR "5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd" OR "dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac" OR "66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd" OR "c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c" OR "e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22" OR "b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb" OR "20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d" OR "dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966" OR "c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14ef" OR "bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7" OR "4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14"
File Hashes
1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7
5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd
dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac
66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd
c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c
e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22
b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb
20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d
dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966
c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14ef
bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7
4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14
Detection Recommendations
In EDR and sandbox telemetry, hunt the twelve SHA-256 values above. Tag 1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7 as the Recipe Lister NSIS installer. Tag the seven FunkSec hashes for Rust ransomware that disables Defender and deletes shadow copies. Tag bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7 as Oyster/CleanBoost. Tag 4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14 as Rhadamanthys. Tag c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14ef as the 360Util COM hijack.
Alert on NSIS installers with near-maximum entropy and uncommon code-signing subjects, Authenticode identities that spoof Dropbox or 360 Total Security, and PDB paths containing Funksec, Darkzone, or Darkfunk.
Do not treat ChatGPT in a filename as an IOC. Unit 42 explicitly classified that pattern as brand abuse wrapping conventional malware.
References
- [Unit 42] The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution (2026-08-25) — https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
- [Unit 42] Analyzing the Current State of AI Use in Malware (prior related research) — https://unit42.paloaltonetworks.com/ai-use-in-malware/