How AI Built the Gryxa Malware Empire

A new report shows how AI can be weaponized, revealing that the Gryxa malware was built by an operator using a commercial AI coding assistant. The attacker used the AI to generate malicious code, craft a control console, and set up an automated update pipeline, bypassing deep programming. This ease of creation signals a troubling evolution.

ReliaQuest’s analysis linked 324 compromised hosts to the operation, showing how AI accelerated scaling. The malware’s console offered monitoring and command execution, while an automated update mechanism let the attacker patch or add capabilities on the fly. Such speed cuts deployment time from weeks to minutes.

The report underscores AI’s dual role—boosting developer productivity while also arming cybercriminals. Security teams must now expect faster, more sophisticated attacks and adopt AI‑driven defenses that respond at machine speed. As AI spreads, the offense‑defense contest will grow automated, demanding threat hunting and vigilant monitoring to thwart the next Gryxa‑style threat.

Source: Read original article

By AI