AskVantage

Security and privacy

Self propagating Zero Click Gen AI worm spreads malware and jailbreaks AI models

Meet your worst nightmare, a self propagating Generative AI developed Worm that evolves and spreads itself autonomously to spread malware and destroy and poison AI models.

Key takeaways

  • The prompts can be used for stealing information, spreading spam, poisoning models, and more.
  • To demonstrate how self-replicating AI malware could work, the researchers created an E-Mail system capable of receiving and sending E-Mails using generative AI.
  • By either of these methods, an attacker could automatically propagate spam, propaganda, malware payloads, and further malicious instructions through a continuous chain of AI-integrated systems.
Cite or link to this article

Griffin, M. (2024) 'Self propagating Zero Click Gen AI worm spreads malware and jailbreaks AI models', 311 Institute, 20 October. Available at: https://www.311institute.com/self-propagating-zero-click-gen-ai-worm-spreads-malware-and-jailbreaks-ai-models/ (Accessed: 1 October 2026).

In what’s an example of yet another innovative and crippling use of technology to do evil a worm that uses clever prompt engineering and prompt injection attacks has been shown to be able to trick Generative Artificial Intelligence (GenAI) apps and models like ChatGPT into propagating malware - and much more.

In a laboratory setting, three Israeli researchers demonstrated how an attacker could design "adversarial self-replicating prompts" that convince a generative model into replicating input as output.

The Future of Cyber Security, by keynote Matthew Griffin

In other words if a malicious prompt comes in, the AI app or model in question will turn around and push it back out, allowing it to spread to further AI agents. The prompts can be used for stealing information, spreading spam, poisoning models, and more.

In a hat tip to the past the researchers have named the worm "Morris II," after the infamous 99-line self-propagating malware which took out a tenth of the entire Internet back in 1988.

To demonstrate how self-replicating AI malware could work, the researchers created an E-Mail system capable of receiving and sending E-Mails using generative AI. Next, as a red team, they wrote a prompt-laced E-Mail which takes advantage of Retrieval-Augmented Generation (RAG) - a method AI models use to retrieve trusted external data - to contaminate the receiving E-Mail assistant's database. When the E-Mail is retrieved by the RAG and sent on to the gen AI model, it jailbreaks it, forcing it to exfiltrate sensitive data and replicate its input as output, thereby passing on the same instructions to further hosts down the line ad infinitum.

The researchers also demonstrated how an adversarial prompt can be encoded in an image to similar effect, coercing the E-Mail assistant into forwarding the poisoned image to new hosts. By either of these methods, an attacker could automatically propagate spam, propaganda, malware payloads, and further malicious instructions through a continuous chain of AI-integrated systems. And that, in the age of chained together AI agents … will be a huge problem.

FAQ

Why does this matter?

Meet your worst nightmare, a self propagating Generative AI developed Worm that evolves and spreads itself autonomously to spread malware and destroy and poison AI models.

Matthew Griffin

About the author

Matthew Griffin Founder, 311 Institute

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."

Read full bio

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.

An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.

As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.

Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.

What future do you need to see?

Choose one to get started on security and privacy and the future of your organisation.

Where should Matthew reply?

Takes 30 seconds. No obligation. Matthew replies quickly. Privacy

Tag Cloud

Starburst opens that technology on the interactive 311 Starburst.

Sources and further reading

  1. named the worm "Morris II," sites.google.com

Source: first published by the 311 Institute on 20 October 2024. Cite as: Griffin, M. (2024). Self propagating Zero Click Gen AI worm spreads malware and jailbreaks AI models. 311 Institute. https://www.311institute.com/self-propagating-zero-click-gen-ai-worm-spreads-malware-and-jailbreaks-ai-models/

You are welcome to quote this article with credit and a link to the original.

Book a Keynote