Cybersecurity
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
Cyber RTJune 9, 20263 min read

University of Toronto researchers developed an AI-driven computer worm that autonomously navigates networks, identifies vulnerabilities, and replicates itself without human intervention. Tested on a 33-host network, it exploited 31.3 vulnerabilities on average and replicated to 62% of the network. Unlike traditional worms, it uses an open-weight large language model to generate attack strategies at runtime, bypassing commercial AI services. The worm highlights challenges in patching vulnerabilities and emphasizes the need for enhanced network segmentation and monitoring.
Researchers at the University of Toronto have developed a proof-of-concept AI-driven computer worm capable of autonomously navigating networks, generating attack strategies, and replicating itself without human intervention. This worm leverages a locally hosted open-weight large language model (LLM) to dynamically create tailored attack paths for each target it encounters, bypassing the need for commercial AI services. The preprint of this study, posted on arXiv, highlights the vulnerabilities in single-CVE patching when faced with malware that can adapt in real-time by inspecting exposed services and reading fresh advisories.
In controlled experiments on a 33-host network designed to be vulnerable, the worm demonstrated its capabilities by identifying an average of 31.3 vulnerabilities and gaining elevated access on 23.1 hosts. It successfully replicated itself to 62% of the network over seven days, despite having no prior knowledge of the network topology and operating without human input. Unlike traditional worms, which rely on fixed exploit payloads, this worm uses an open-weight LLM to generate attack logic at runtime, allowing it to adapt to each new target it encounters.
The research team, led by associate professor Nicolas Papernot, conducted 15 independent experiments on a network named "FakeCorp," which included various operating systems and IoT devices. The worm utilized a shared GPU inference pool to simulate compute resources from compromised machines, achieving a 68.8% success rate in full GPU-tier replication. Infected GPU-capable hosts acted as distributed reasoning nodes, providing inference for devices on the network that lacked the computational power to run the model themselves.
During these experiments, the worm achieved elevated access on 23.1 hosts and launched replicas on 88% of them, reaching up to seven generations of self-replication. The worm's success was attributed to its ability to autonomously reason through individual vulnerabilities rather than exploiting a mostly hardened production network. It executed a variety of exploits, including SambaCry, Dirty Pipe, and PrintNightmare, by reasoning its way to them based on the vulnerabilities it discovered on each host.
The worm's ability to bypass its training cutoff by ingesting public advisory text at runtime allowed it to exploit vulnerabilities disclosed after its training, such as CVE-2026-39987 and CVE-2026-31431. This capability highlights the challenges posed by the patching-window problem, where adaptive worms can continue testing new attack paths while defenders are still working on validating fixes. The worm's design, which operates without vendor dependency, makes it difficult to contain using traditional methods like API key revocation.
This research is part of a broader trend in AI-driven malware, with previous studies like Morris II and ClawWorm exploring similar concepts. However, the Toronto worm is unique in that it uses an LLM as the attack engine to compromise network infrastructure, rather than being the target of the attack. Real-world operations have already seen AI-orchestrated espionage campaigns, and the Toronto worm represents a lab version of this direction, focusing on host-level worm propagation.
To counter such threats, defenders are advised to segment GPU-capable machines, treat published advisories as immediate weaponization targets, and rotate credentials on compromised hosts. Monitoring for specific behavioral signals, such as non-standard port activity and unexpected LLM inference, can help detect and mitigate the worm's impact. The University of Toronto plans to establish a vetting process for qualified defensive researchers to access the implementation for further study and defense development.


