On October 8, 2026, Cisco Talos published new findings from its CAIRN research revealing that malware authors are embedding natural-language instructions into code to evade AI-assisted analysis.
Evasion Techniques Tracked Over 18 Months
Cisco Talos classified this growing threat trend as "A3: AI-Analysis Evasion." Over the past 18 months, researchers tracked techniques ranging from simple comments telling an AI to ignore a file to advanced template spraying designed to trick specific large language models.
According to Talos, these prompt-injection techniques steer the AI's verdict in the attacker's favor about 35 percent of the time. Malware families leveraging A3, such as MANTLEMAZE, also combine these AI deceptions with underlying threats like abusing vulnerable drivers to disable EDR from kernel space.
Detection and Defense Guidance
Because evasion instructions must be written in plaintext, defenders have a highly stable detection surface to monitor. Security teams should flag imperative language addressed to analysis systems within binaries as a suspicious signal.
Cisco Talos stated that anyone building or using AI-assisted pipelines must ensure text extracted from a sample is strictly treated as evidence and never as a system directive.
What to do
- Flag imperative language addressed to analysis systems within binaries as a suspicious signal.
- Ensure that text extracted from a sample is strictly treated as evidence, never as a system directive.
Key facts and where they come from
- Cisco Talos disclosed findings from CAIRN research showing malware authors embed natural-language instructions into code to evade AI-assisted analysis.
Cisco Talos is disclosing new findings from our CAIRN research that show malware authors are embedding natural-language instructions into their code to evade AI-assisted analysis.
- Talos classifies this trend as A3: AI-Analysis Evasion.
We classify this growing trend as "A3: AI-Analysis Evasion."
- Techniques tracked over the past 18 months range from simple comments to template spraying targeting LLMs.
Over the past 18 months, we've tracked techniques ranging from simple comments telling an AI to ignore a file, to advanced "template spraying" designed to trick specific large language models (LLMs).
- Prompt-injection techniques steer the AI verdict in the attacker's favor about 35 percent of the time.
prompt-injection techniques only steer the AI's verdict in the attacker's favor about 35 percent of the time
- A3 families like MANTLEMAZE pair AI deceptions with threats such as abusing vulnerable drivers to disable EDR from kernel space.
A3 families like MANTLEMAZE also pair these AI deceptions with serious underlying threats, such as abusing vulnerable drivers to disable EDR from kernel space.
