Researchers demonstrated a self-spreading piece of malware that uses AI to invent a fresh attack approach for each machine it encounters, rather than relying on a fixed set of known vulnerabilities. It runs freely available AI models on the machines it has already compromised, so it needs no commercial AI service and cannot be stopped by a provider blocking requests. The demonstration ran on a test network of Linux, Windows and connected-device machines using common corporate weaknesses.
What changed
Traditional worms such as WannaCry relied on fixed, predetermined vulnerabilities, so patching those holes stopped their spread.
What it unlocks
Demonstrates self-propagating malware that writes new attack strategies for each machine it meets, without any human operator or commercial AI service.
- marginal cost per new infection of zero
- tested across Linux, Windows and IoT devices
- arxiv.org2026-08-03