Executive Summary
In early 2024, cybersecurity researchers identified a new campaign where advanced persistent threat (APT) groups incorporated large language models (LLMs) into malware strains to dynamically evade traditional security controls. Attackers leveraged generative AI prompts at runtime to modify payloads, change behavior signatures, and bypass both heuristic and signature-based detection solutions. This innovation enabled lateral movement within compromised environments, facilitated egress of sensitive data, and complicated incident response due to the malware's adaptive techniques. Several enterprise and public sector networks were affected, leading to significant operational disruptions and raising concerns about advanced AI-powered threats.
The incident underscores a rapidly escalating trend: cybercriminals are weaponizing AI and LLMs to outpace enterprise defenses, blending evasion, lateral movement, and multi-cloud attack vectors. The urgency is heightened as regulatory frameworks evolve and organizations race to adopt zero trust, segmentation, and advanced anomaly detection to keep pace.
Why This Matters Now
Malware using LLMs represents a fundamental shift in attacker capability, enabling real-time adaptation and evasion inside modern hybrid-cloud and zero trust architectures. This urgent threat disrupts existing security controls and mandates immediate investment in AI-driven detection, deep segmentation, and continuous visibility to counter rapidly evolving attack techniques.
Attack Path Analysis
Attackers leveraged LLM-enhanced malware to gain an initial foothold via exposed cloud services or weak credentials. They escalated privileges by exploiting misconfigured roles or automated script generation from LLMs. The adversaries moved laterally across internal east-west traffic, possibly targeting container workloads or sensitive data stores. Command and Control was maintained using encrypted or obfuscated channels to evade detection. Data exfiltration occurred through stealthy outbound channels, leveraging AI to adapt to policy evasion. Finally, the attackers launched impact actions such as data deletion or ransomware deployment to disrupt the business.
Kill Chain Progression
Initial Compromise
Description
Malware leveraging LLMs gained initial access to cloud environments by exploiting weak credentials, vulnerable interfaces, or poorly secured APIs, possibly aided by AI-generated evasion.
Related CVEs
CVE-2025-10164
CVSS 7.3A remote code execution vulnerability in SGLang's /update_weights_from_tensor endpoint due to unsafe deserialization of untrusted data.
Affected Products:
SGLang Large Model Inference Framework – All versions prior to the patched release
Exploit Status:
proof of conceptCVE-2025-23254
CVSS 8.8Insecure deserialization in NVIDIA TensorRT-LLM's Python executor component allows local attackers to execute arbitrary code.
Affected Products:
NVIDIA TensorRT-LLM – Versions prior to 0.18.2
Exploit Status:
no public exploitCVE-2025-53773
CVSS 9Remote code execution vulnerability in GitHub Copilot and Visual Studio Code through prompt injection, allowing attackers to modify settings and execute arbitrary commands.
Affected Products:
GitHub Copilot – Versions prior to the patched release
Microsoft Visual Studio Code – Versions prior to the patched release
Exploit Status:
proof of conceptReferences:
MITRE ATT&CK® Techniques
Obfuscated Files or Information
Subvert Trust Controls: Code Signing
Shared Modules
User Execution
Command and Scripting Interpreter
Masquerading
Native API
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Log security events and retain logs
Control ID: 10.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Continuous Threat Detection and Response
Control ID: Detect Function - Continuous Monitoring
NIS2 Directive – Cybersecurity Risk-management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
LLM-augmented malware poses severe APT risks to financial institutions, potentially evading traditional security controls and compromising encrypted transactions and customer data.
Health Care / Life Sciences
Runtime LLM malware adaptation threatens HIPAA compliance and patient data protection, exploiting healthcare's complex multi-cloud environments and legacy security systems.
Computer Software/Engineering
Software companies face direct exposure as threat actors weaponize AI technologies, creating adaptive malware that challenges existing detection capabilities and security frameworks.
Government Administration
APT groups using LLM-enhanced malware present critical national security risks, potentially bypassing zero trust architectures and compromising sensitive government operations.
Sources
- How Malware Authors Are Incorporating LLMs to Evade Detectionhttps://www.darkreading.com/threat-intelligence/malware-authors-incorporate-llms-evade-detectionVerified
- Hackers Begin Using LLM Models to Develop 'Intelligent Malware' Capable of Real-Time Evasionhttps://www.thaicert.or.th/en/2025/11/28/hackers-begin-using-llm-models-to-develop-intelligent-malware-capable-of-real-time-evasion/Verified
- 10 Ways Cybercriminals Can Abuse Large Language Modelshttps://www.forbes.com/councils/forbestechcouncil/2023/06/30/10-ways-cybercriminals-can-abuse-large-language-models/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF Zero Trust segmentation, east-west traffic controls, and multi-cloud visibility could have prevented lateral spread and detected AI-driven evasions. Encrypted traffic inspection, strict egress enforcement, and real-time anomaly detection would have disrupted C2 and exfiltration, limiting adversary impact.
Control: Zero Trust Segmentation
Mitigation: Unauthorized access prevented by minimizing attack surface.
Control: Zero Trust Segmentation
Mitigation: Cross-segment privilege escalation blocked.
Control: East-West Traffic Security
Mitigation: Lateral movement detected and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound C2 channels disrupted.
Control: Encrypted Traffic (HPE)
Mitigation: Data exfiltration attempts detected and prevented.
Destructive operations promptly detected and mitigated.
Impact at a Glance
Affected Business Functions
- IT Operations
- Data Security
- Software Development
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive data due to malware's ability to dynamically generate and execute malicious code, evading traditional detection mechanisms.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation to strictly isolate workloads and minimize blast radius from initial compromise.
- • Enforce fine-grained east-west inspection to detect and prevent internal lateral movement exploiting cloud resources.
- • Implement robust egress filtering and inline IPS to disrupt obfuscated command & control and exfiltration channels.
- • Enable high-performance encryption and traffic observability to surface anomalies in encrypted outbound flows.
- • Continuously monitor with cloud-native anomaly detection and automated incident response to rapidly contain evolving, AI-driven threats.



