Skip to content

Malware uses AI tools as camouflage for malicious activities

In brief: Malware is beginning to abuse established AI tools to camouflage malicious actions, making detection by security teams more difficult.

Attackers are developing malware such as Sandworm_Mode, which abuses trusted AI tools and workflows to make attack activities barely distinguishable from normal operations.

The malware specimen Sandworm_Mode demonstrates a new attack pattern: instead of classic exploitation, the trustworthiness of legitimate AI tools is leveraged to weave malicious activities into normal operational processes.

For CISOs, this means an expansion of the attack surface: not only external malware becomes a vector, but also the company’s own or standardized AI workflows. These tools are designed by default to process data and generate outputs – a characteristic that attackers can exploit for obfuscation purposes.

The consequence lies in detection: security analyses that work toward identifying known malware signatures or anomalous process flows lose effectiveness when attack patterns become invisible within authorized tools. Enhanced monitoring at the AI tool level – such as through logging of input and output parameters as well as abnormal frequencies – becomes necessary.


Source: www.darkreading.com · Published 22 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: