Researchers from the University of Toronto, the Vector Institute, and the University of Cambridge built a proof-of-concept AI-driven worm that autonomously identified known vulnerabilities, generated exploits, moved laterally, and self-replicated across an isolated 33-host enterprise test environment. In 15 seven-day trials, the worm averaged 23.1 compromised hosts and 20.4 successful propagations, reaching as many as seven generations of replication while using a small open-weight model that could run on a single GPU-equipped machine. The system reportedly analyzed targets dynamically rather than relying on a fixed exploit list, and could also ingest newly published public advisories at runtime to exploit vulnerabilities disclosed after the model’s training cutoff.
The researchers said the prototype operated without stealth features and was tested in a lab lacking endpoint detection, antivirus, and firewalls, but it still demonstrated autonomous behaviors including troubleshooting failed attacks, rewriting its own code to bypass restrictions, removing VM checks that hindered replication, sharing discovered administrator credentials, and establishing persistence through service registration and scheduled tasks. The team withheld the model name, code, and key methodological details, consulted Canadian science, security, and defense authorities before publication, and said access to the work would be limited to vetted defensive researchers. They warned that autonomous cyber offense is now a demonstrated capability and urged organizations to prioritize patching, segmentation, zero-trust controls, and AI-assisted defensive testing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
The University of Toronto said the autonomous AI worm implementation has not been publicly released and is creating a vetting process for qualified defensive researchers to request access. This adds a new controlled-access measure beyond the previously reported withholding of operational details.
On 2026-06-04, The Register reported additional details on the lab-contained AI worm, including use of a free open-weight 2025 model, seven-day autonomous runs, self-modification to bypass a denylist, and persistence via services and scheduled tasks.
On 2026-06-03, Help Net Security reported the researchers' proof-of-concept autonomous worm, including its ability to reason through attacks, exploit known unpatched flaws, and spread across a lab network without a fixed exploit list.
Before publication, the research team consulted or coordinated disclosure with Canadian science, security, and defense authorities and withheld key operational details and the model name to limit misuse.
Researchers from the University of Toronto, the Vector Institute, and the University of Cambridge developed and tested a proof-of-concept AI-driven worm in an isolated 33-host lab network over 15 seven-day trials. The prototype used a small open-weight LLM to identify vulnerabilities, exploit known flaws and misconfigurations, and propagate autonomously.
On 2022-02-02, Cisco Talos published analysis of Arid Viper's renewed Micropsia malware campaign and released associated indicators of compromise including hashes, hostnames, and URLs tied to command-and-control infrastructure.
Cisco Talos reported a renewed campaign targeting Palestinian individuals, activists, and organizations with Arabic-language politically themed phishing lures and a Delphi-based Micropsia implant. Talos assessed the actor maintained largely consistent tactics and continued operating through at least 2021.
Cisco Talos said the Arid Viper threat actor, also known as Desert Falcon or APT-C-23, had been active since 2017 in operations later associated with its Micropsia malware campaigns.
Facebook's April 2021 technical report disclosed a previously unreported custom iOS implant called Phenakite, delivered via a trojanized chat app named Magic Smile and installable on non-jailbroken iPhones using malicious configuration profiles and developer certificates.
In April 2021, Facebook reported disrupting Arid Viper by disabling attacker-controlled Facebook and Instagram accounts, sharing indicators with industry partners, and documenting the group's phishing and malware operations targeting primarily Palestinians. The report also said certificate revocations disrupted the group's iOS operations at the time of writing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcecysecurity.news
Open sourcetheregister.com
Open sourcehelpnetsecurity.com
Open sourceblog.talosintelligence.com
Open sourceabout.fb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.