Cisco Talos documents malware that tries to prompt-inject AI security analysts
Cisco Talos' CAIRN research classifies a new malware archetype, 'A3: AI-Analysis Evasion,' where malicious code embeds natural-language text designed to manipulate language models used in automated malware triage. Talos traced the technique across four malware families (FRUITSHELL, PLOTSAFE, HOLLOWCLAD, MANTLEMAZE) and 84 samples from January 2025 to July 2026, showing it spreading from a simple copy-pasted comment to templated, multi-model-targeted 'template spraying' and fake intimidation messages. Controlled testing with a panel of five local LLMs found the simplest direct-instruction technique shifted model verdicts toward 'benign' in roughly 35% of runs, while more elaborate tricks had little effect or backfired by increasing suspicion.