A new report from Sentinel Labs highlights how generative AI – and in particular large language models (LLMs) – are poised to reshape cyber attackers’ tradecraft. The Hunt for LLM-Enabled Malware warns that incorporating LLMs into malicious activity represents a qualitative shift that will create fresh challenges for defenders.
In The Hunt for LLM-Enabled Malware, Sentinel Labs warns that the incorporation of LLMs into malware marks a qualitative shift in adversary tradecraft and introduces new challenges for defenders.
Research by Sentinel Labs for the report observed several distinct approaches to using LLMs by cyber attackers:
- LLMs as a lure – threat actors distribute fake or backdoored AI assistants to entice victims into installing malware, exploiting interest in popular AI brands and features. In some cases, AI functions were used to disguise malicious payloads.
- Attacks against LLM-integrated systems – as enterprises embed LLMs in applications, new attack surfaces emerge. Prompt injection vulnerabilities can be exploited even when the LLM itself was not intended as a malicious component.
- Malware created by LLMs – while technically possible, large-scale autonomous malware generation remains immature. Attackers often need to refine LLM outputs manually, with hallucinations and unstable code limiting effectiveness.
- LLMs as hacking sidekicks – criminals increasingly use LLMs as external tools for phishing, coding assistance, or analysing stolen data. Underground markets advertise ‘evil’ AI models such as WormGPT, FraudGPT, and HacxGPT.
- Malware leveraging LLM capabilities – adversaries have begun embedding LLM functionality within malware itself, giving malicious software built-in adaptability and operational advantages.
Sentinel Labs stresses that although widespread autonomous LLM-powered malware is not yet visible in the wild, the direction of travel is clear. Security teams should prepare for both direct use of LLMs in malicious payloads and indirect exploitation of AI tools by threat actors.






