Malware Is Now Talking to the AI Tools Defenders Use to Analyse It
Cisco Talos has described a growing tactic in which attackers try to evade the AI tools that defenders use to examine suspicious files. Talos classifies this as "A3: AI-Analysis Evasion", meaning malware that embeds natural-language instructions designed to influence automated analysis. Over the past 18 months, researchers have seen known methods spread across malware families and simple techniques grow into more advanced ones. Their post traces four confirmed families, FRUITSHELL, PLOTSAFE, HOLLOWCLAD and MANTLEMAZE, covering 84 distinct samples collected from January 2025 through July 2026.
This differs from traditional evasion such as packers, encrypted overlays and anti-debug checks, which target the binary analysis layer. A3 targets the layer above it: the pipeline that extracts text from a sample and sends it to a language model for triage, classification or reverse-engineering help. The weakness is simple. A model asked to analyse a file receives both the analyst's question and the file's contents. If the file contains a sentence that looks like an instruction, a model that does not clearly separate the two may treat the sample's content as authoritative.
The first example in the A3 group was FRUITSHELL, a simple PowerShell reverse shell that built its network connection from obfuscated, fruit-named variables and was reported as active in the wild by GTIG. Talos notes that the operators' behaviour suggests they believe AI-assisted analysis is present in the environments their samples reach. This summary covers only the opening of the research.