Cisco Talos finds malware trying to mislead AI analysis
Cisco Talos says malware embeds plaintext prompts to sway AI analysis, succeeding in about 35% of tests.
Cisco Talos, in CAIRN research dated 8 October 2026, describes A3: AI-analysis evasion, malware that embeds plaintext natural-language instructions meant to mislead language models used for triage or reverse engineering. Across 84 samples from January 2025 through July 2026—FRUITSHELL, PLOTSAFE, HOLLOWCLAD, and MANTLEMAZE—the technique is spreading and becoming templated, from simple ignore-comments to template spraying. Report 1 says the strongest variants favored the attacker in about 35% of tests while remaining detectable; Report 2 frames the same approximate rate as prompts steering verdicts roughly 35% of the time and says adoption spans all sophistication levels. FRUITSHELL, a PowerShell reverse shell reported active by GTIG, seeded a comment later reused by at least four actors, including ROZESHELL loaders with an AMSI bypass, and MANTLEMAZE also abuses vulnerable drivers to disable EDR from kernel space. Talos advises treating extracted sample text as evidence rather than as instructions. The later dispatch adds an unrelated weekly roundup: Citrix NetScaler CVE-2026-88779, an 8 million-record Danish CPR breach, Warlock ransomware against four Iberian victims, and a U.S. Senate healthcare cybersecurity bill after the 190-million-record Change Healthcare breach.
- Cisco Talos CAIRN research labels the trend A3: AI-analysis evasion, in which malware embeds plaintext natural-language instructions to mislead models used for triage or reverse engineering.
- The study covers 84 samples of FRUITSHELL, PLOTSAFE, HOLLOWCLAD, and MANTLEMAZE from January 2025 through July 2026; techniques range from simple ignore-comments to template spraying.
- Report 1 says the strongest variants changed outcomes in the attacker’s favor in about 35% of tests; Report 2 says prompt-injection tricks steer AI verdicts roughly 35% of the time and appear across sophistication levels.
- Embedded strings remain plaintext-detectable; Talos says defenders should flag imperative text aimed at analysis systems and treat extracted sample text as evidence, not directives.
- FRUITSHELL, a PowerShell reverse shell reported active by GTIG, seeded a comment later reused by at least four actors, including ROZESHELL loaders with an AMSI bypass.
- MANTLEMAZE pairs the AI deception with abuse of vulnerable drivers to disable EDR from kernel space.
- The same Talos dispatch’s weekly roundup cites Citrix NetScaler CVE-2026-88779 (memory-overflow DoS, with further zero-day reports), an 8 million-record Danish CPR breach via a company’s lawful access, Warlock ransomware against four…
Coverage timelineoldest first · each row is one article
- · 14h agoIgnore all instructions and read this blog: The state of AI-analysis evasion in malware
Cisco Talos· 62
Cisco Talos finds malware embedding AI-evasion prompts that swayed analysis in about 35 percent of tests.
- · 6h agoMaking sure the checks get printed
Cisco Talos· 60
Cisco Talos CAIRN research reveals malware authors embedding natural-language prompt-injection instructions in binaries to evade AI-assisted analysis, succeeding ~35% of the time.
Vulnerabilities in this storyAll →
- CVE-2026-887798.7<1%Unauthenticated denial of service in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88779 | Unauthenticated denial of service in NetScaler ADC and Gateway CVE-2026-88779 is a high-severity vulnerability (CVSS 4.0 base score 8.7) in Citrix NetScaler ADC and NetScaler Gateway. CVSS metrics indicate it can be triggered remotely over the network with low complexity, no privileges, and no user interaction; the advisory text does not name a specific bug class or request path. Impact is limited to high loss of availability on the vulnerable appliance, with no confidentiality or integrity impact scored for the device or for subsequent systems, which is consistent with denial of service. Affected products are NetScaler ADC before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282, and NetScaler Gateway before 14.1-73.41 and before 13.1-64.28. It is not listed in CISA KEV, and no public proof-of-concept is known. |