Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app.
The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target.
Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert records generated whenever a sample actually ran. Only 12 hashes surfaced on live endpoints, while a somewhat larger group (15-20 hashes) appeared in network sandbox traffic. Every one of the 12 samples detected on protected endpoints triggered a security alert.
The samples that never reached production fall into three groups. The largest is proof-of-concept code built to demonstrate a technique: configured to target only local or private networks, filled with debug output no real attacker would leave behind, and uploaded once by a research lab or university.
A second group comes from organizations testing their own defenses against previously reported AI malware, identifiable by repeated uploads of the same file from the same source in a short window. A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products with no actual AI functionality behind them.







