Skip to content
Toronto and Cambridge team builds AI worm that hacks and infects 61.8% of test network

Toronto and Cambridge team builds AI worm that hacks and infects 61.8% of test network

Dongascience June 5, 2026

A new form of computer malware (worm) has been developed that uses artificial intelligence (AI) to autonomously identify vulnerabilities in target systems, launch attacks, and propagate to other devices. Experts warn that AI-based cyberattacks are no longer just a theoretical possibility and say we must prepare for this new security threat.

According to a report on the 3rd (local time) by U.S. science outlet Scientific American , a joint research team from the Vector Institute at the University of Toronto in Canada and the University of Cambridge in the U.K. implemented a computer worm that uses AI to generate its own attack strategies and self-replicate, then tested its propagation capability in a virtual network. The results were published on the preprint server 'arXiv' on the 2nd.

A computer worm is malicious code that replicates itself over a network and spreads to other systems without user intervention. Conventional worms operate according to commands predefined by their developers, but the new AI worm is designed to use AI to adapt to and learn from new environments.

The team tested the AI worm in an isolated virtual environment rather than on the real internet. They conducted 15 experiments in a simulated corporate network consisting of 33 devices, including Linux, Windows, and Internet of Things (IoT) devices.

In the experiments, the AI worm identified an average of 31.3 vulnerabilities and obtained administrator privileges on 23.1 systems. It then self-replicated to an average of 20.4 systems, ultimately spreading to 61.8% of the entire network.

The researchers explained that AI worms are more dangerous than existing malware. Traditional worms can only exploit vulnerabilities that developers have specified in advance, whereas AI worms first reconnoiter the target system and then generate attack strategies in real time that fit the situation. Even if a specific attack fails, they attempt new methods based on the information they have collected.

The AI worm also successfully exploited three vulnerabilities that were disclosed only after the large language model (LLM) training had been completed. By reading publicly available security advisories, it autonomously composed new attack methods. The team expressed concern that, once a new vulnerability is disclosed, an AI worm could launch attacks before companies have time to apply security patches.

Notably, the AI worm used publicly available AI models that anyone can access on the internet, rather than proprietary corporate models. The researchers said this demonstrates that the technical barriers to developing high-performance AI-powered malware have been lowered.

At the same time, they pointed out that cyber security risks have grown because most critical infrastructure in modern society—including financial systems, telecommunications networks, healthcare systems, and transportation systems—is interconnected via networks.

David Lee, a professor at the University of Toronto who was not involved in the research, said this is a "warning that we must urgently develop defensive technologies to counter AI-enhanced cyberattacks," adding that "AI can be used not only to advance offensive techniques but also to develop defensive technologies." In other words, because AI can detect vulnerabilities, it can also be used to remedy them and build response systems.

doi.org/10.48550/arXiv.2606.03811

Extracted Entities

Domains (1)