Friday, October 9, 2026 Newsletter Advertise
Latest
Cyber news

Cisco Talos Details Malware Using AI-Analysis Evasion

Cisco Talos tracked malware families embedding natural-language instructions to manipulate automated AI security analysis.

Cisco Talos Details Malware Using AI-Analysis Evasion. CVE-2015-2291, Source: Cisco Talos

Cisco Talos published a threat report on October 8, 2026, detailing malware families that embed natural-language instructions designed to obstruct automated artificial intelligence analysis.

The A3 Malware Archetype

According to Cisco Talos, malware authors are developing techniques to obstruct automated AI analysis, a trend classified as A3: AI-Analysis Evasion. Researchers defined this archetype as malware embedding natural-language instructions to influence triage, classification, or reverse-engineering assistance.

Cisco Talos traced these techniques across 84 distinct samples collected from January 2025 through July 2026, spanning four confirmed malware families: FRUITSHELL, PLOTSAFE, HOLLOWCLAD, and MANTLEMAZE. The simplest technique involves adding direct comments telling AI models to ignore the file.

Evasion Sophistication and Testing

The techniques have evolved from copy-pasted comments in FRUITSHELL to template spraying in HOLLOWCLAD and MANTLEMAZE, where authors attempt to match multiple large language model chat formats. MANTLEMAZE samples also present themselves as proprietary intellectual property and include fabricated government contracts and certifications alongside a PDB path referencing the iqvw64e.sys Bring-Your-Own-Vulnerable-Driver target (CVE-2015-2291).

Cisco Talos evaluated the effectiveness of these strings by testing them across local large language models. The organization reported that the best techniques steered outcomes in the attacker's favor in about 35% of test runs, while complex options often backfired by increasing model suspicion.

Defender Recommendations

Cisco Talos stated that evasion content must remain plaintext, providing defenders with a stable detection surface. Legitimate software has no reason to embed instructions telling an analyzer to refuse analysis or claim government contracts.

The primary defense recommended by researchers is ensuring that text inside a sample is always treated as evidence rather than instruction, with prompt construction explicitly separating the two boundaries.

What to do

  • Treat text inside a sample as evidence and never as an instruction.
  • Target imperative language addressed to an analysis system found in a binary as a suspicious signal.
Key facts and where they come from
  • Cisco Talos classifies malware embedding natural-language instructions to influence automated analysis as A3: AI-Analysis Evasion.
    we classify this archetype of malware as “A3: AI-Analysis Evasion” — that is, malware that embeds natural-language instructions to influence automated analysis.
  • Talos tracked 84 distinct samples across four A3 families collected from January 2025 through July 2026.
    This post traces these techniques across four confirmed A3 malware families: FRUITSHELL, PLOTSAFE, HOLLOWCLAD, and MANTLEMAZE, representing 84 distinct samples collected from January 2025 through July 2026.
  • The best AI-evasion techniques steered outcomes in the attacker's favor in about 35% of test runs.
    the best techniques steered the outcome in the attacker’s favor in about 35% of test runs.
  • MANTLEMAZE includes a program database path for iqvw64e.sys, a BYOVD target designated as CVE-2015-2291.
    This is the Intel Ethernet diagnostics driver and the Bring-Your-Own-Vulnerable-Driver (BYOVD) target (CVE-2015-2291)

Read the original from Cisco Talos →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber