AI Safety

New AI Worms Can Hack Networks and Copy Themselves

Self-spreading AI malware could attack your company's network with zero human help.

Deep Dive

Computer worms are malware that copies itself from machine to machine, like a digital cold. The new twist is AI. Researchers created a worm that uses large language models (AI that understands and generates text) to look at each new computer it infects and figure out the best way to attack it. Older worms were dumb — they could only do one trick. This AI worm adapts, so it's much harder to stop.

What makes this scary for you and your workplace is the economics. The worm runs on open-weight models (free AI software that anyone can download and run). It steals computing power from the machines it infects, so the attacker's cost per new infection is zero. Meanwhile, defenders must keep paying for monitoring, patching, and response. That's a lopsided fight against a self-replicating, self-improving attacker. Think of it as an intruder who keeps making copies of themselves and their tools, using your own building's electricity to do it.

The researchers say this is not theoretical. They built and tested these worms this year on networks with Linux, Windows, and Internet-of-Things (smart devices like cameras or thermostats) machines. They warned that common corporate network weaknesses are enough for these worms to spread. Since the AI runs locally on infected machines, it doesn't need permission from any cloud company or platform, so normal AI safeguards like content filters or rate limits don't apply.

There's one bright spot: the research was aimed at helping defenders understand the threat before criminals perfect it. But the authors make clear that AI-driven, self-sustaining cyberattacks are here now — and your company's IT team should be paying attention.

Key Points
  • AI worms are self-replicating malware that adapt their attacks to each new victim, unlike older, static viruses.
  • They run on free, open-weight AI models and steal computing power, so attackers pay nothing per infection.
  • Researchers tested these worms this year on real corporate vulnerabilities, showing the threat is current, not future.
  • Because they don't rely on commercial AI platforms, standard safety filters and limits can't stop them.

Why It Matters

Your employer's network, smart devices, and data are at risk from attacks that spread and adapt on their own.

📬 Get the top 10 AI stories daily