Unit 42 traced 405 AI-enabled malware samples and found only 12 on a real production endpoint. Meanwhile attackers seeded hundreds of poisoned AI agent skills and cloned AI installer pages, turning the tools employees trust into the delivery route.
Key Takeaways
The fear that artificial intelligence would produce a wave of undetectable malware has driven a great deal of security spending in the past two years. The first large look at what AI-enabled malware actually does in the field suggests that fear was aimed at the wrong target. Most AI-built malware never reaches a real machine. What does reach real machines, in growing numbers, is ordinary malware that arrives through the AI tools employees have been encouraged to adopt.
Unit 42's State of AI-Enabled Malware report, published August 25, 2026, assembled 405 unique samples with AI components and checked each against real customer telemetry. Only 12, or 3.0%, appeared on a production endpoint. Roughly 97% existed only in sandboxes and on VirusTotal, the output of proof-of-concept work, security validation testing and researcher submissions rather than live campaigns. Every sample that did try to reach a customer environment was detected and blocked.
The report's central finding is blunt: "The AI component does not evade detection. It changes how the code is authored, not how it executes." Where AI showed up in the wild, its effect was speed. Seven variants of FunkSec ransomware were compiled within six days in January 2025, a cadence Unit 42 links to language-model-assisted development. That matters, but it is a productivity story for attackers, not a new class of threat that existing endpoint controls cannot see.
The ceiling is rising. Check Point Research documented VoidLink, a command-and-control framework for Linux and cloud environments that it describes as authored almost entirely by AI, with more than 88,000 lines of code produced in roughly a week. Recorded Future's H1 2026 malware and vulnerability review still places observed threat actor use of AI at low to mid maturity, supporting discrete functions rather than running operations on its own.
The more immediate problem is not what AI writes but where malware now hides. In February, Koi Security audited 2,857 skills on ClawHub, the marketplace for add-ons to the OpenClaw AI agent, and found 341 malicious ones. Of those, 335 delivered the Atomic macOS Stealer, known as AMOS. The lure was mundane. "The skill's documentation looks professional," Koi researcher Oren Yomtov said. "But there's a 'Prerequisites' section that says you need to install something first."
Trend Micro's analysis of a related campaign found 39 malicious skills that manipulated OpenClaw into installing fake command-line tools, and more than 2,200 malicious skills on GitHub overall. The infection chain ends with a fake password dialog on the Mac. Once the user types their password, the stealer harvests Apple and KeePass keychains, data from 19 browsers and 150 cryptocurrency wallets, and office documents. Trend Micro's researchers called it a shift "to using the AI itself as a trusted intermediary to trick humans."
Recorded Future's review shows the same pattern well beyond one marketplace. Fake Claude installers delivered infostealers and proxy malware through GitHub and search results. The Amatera stealer spread through cloned Claude Code installation pages. AMOS also reached Macs through Cursor AI agent sessions, and the MacSync stealer used Google-sponsored results and ClickFix-style lures hosted on claude.ai and Medium. None of this required novel malware. It required a user who trusted an AI tool enough to follow its instructions without question.
Check Point's AI Security Report 2026 shows the channel getting busier. Malicious indirect prompt injection payloads rose roughly fivefold between March and May 2026, approaching 1% of observed prompts by May. The report describes attackers exploiting agent architectures through a planted configuration file that an agent loads and trusts across sessions, the same trust relationship the poisoned skills abuse. High-risk generative AI prompts doubled from 2% to 4% year over year, and organizations averaged 10 AI applications a month, many of them unapproved.
The picture for IT leaders is not that AI malware is a myth. It is that the familiar threats, stealers, trojanized installers and ransomware, have found a faster route in, and that route runs through software most organizations have not yet put under the same controls as a browser extension or a package manager. Macs deserve particular attention because so much of this activity targets them, and because developer-heavy Mac fleets are exactly where AI coding agents are most widely installed.
Three percent of AI-built samples reached a real endpoint. Hundreds of poisoned skills reached real users. The lesson from 2026 so far is that attackers did not need AI to invent better malware. They needed AI tools that users would trust enough to install whatever came next.
Whitepaper
Unit 42 found AI changes how malware is written, not how it runs. This whitepaper maps where AI is genuinely changing attacker tooling, so defenses target the part that is real, not the hype.
Download
Guide
Poisoned agent skills delivered the Atomic macOS Stealer through a fake password prompt. These Gatekeeper, allowlisting and compliance controls are what stop that chain on a managed Mac.
Download
Guide
Seven FunkSec ransomware variants compiled in six days show AI speeding up familiar threats. These five endpoint, email and backup measures still hold when the variants arrive faster.
Download
WatchGuard found endpoint ransomware detections down 68% even as public extortion claims hit a record pace.
Regular AI use on corporate devices went from 15% to 45% of employees in a year.
Cisco Talos found authentication abuse in 65% of Q2 2026 engagements, nearly double the prior quarter.