In brief: Malware is beginning to abuse established AI tools to camouflage malicious actions, making detection by security teams more difficult.
Attackers are developing malware such as Sandworm_Mode, which abuses trusted AI tools and workflows to make attack activities barely distinguishable from normal operations.
The malware specimen Sandworm_Mode demonstrates a new attack pattern: instead of classic exploitation, the trustworthiness of legitimate AI tools is leveraged to weave malicious activities into normal operational processes.
For CISOs, this means an expansion of the attack surface: not only external malware becomes a vector, but also the company’s own or standardized AI workflows. These tools are designed by default to process data and generate outputs – a characteristic that attackers can exploit for obfuscation purposes.
The consequence lies in detection: security analyses that work toward identifying known malware signatures or anomalous process flows lose effectiveness when attack patterns become invisible within authorized tools. Enhanced monitoring at the AI tool level – such as through logging of input and output parameters as well as abnormal frequencies – becomes necessary.
Source: www.darkreading.com · Published 22 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.