Researchers Prototype AI-Powered Internet Worm

Bruce Schneier says researchers have prototyped an AI-powered internet worm. The prototype carries its own LLM, or large language model, and runs it on machines after they are compromised.

Researchers Prototype AI-Powered Internet Worm

Security researcher Bruce Schneier says researchers have prototyped an AI-powered internet worm, a new twist on malware that can carry its own language model and run it on systems it has already broken into.

Schneier described the work in a June 5 post on Schneier on Security, linking to the prototype and to a New York Times report about scientists finding a way to supercharge dangerous computer worms with AI. He said the prototype is notable because it brings its own LLM, short for large language model, instead of relying on a remote AI service.

⚡ New to this?

A worm is a type of malware that spreads on its own from one computer to another. An LLM, or large language model, is the kind of AI system that can generate and process text, and in this case the researchers built one into the malware itself.

That matters because it suggests malicious software may not need to depend on outside AI services once it gets onto a machine. For security teams, that changes the shape of the threat: the AI can move with the malware instead of living only in the cloud.

🦞 OpenClaw angle

If you run self-hosted agents, treat any local model runtime as part of the attack surface, not just the app around it. Put strict network egress controls around agent hosts so a compromised process cannot spread or call home freely, and isolate model files, tools, and credentials from the agent container or VM.

Also review how your automation handles untrusted input and tool use. If an agent can write files, execute shell commands, or reach internal services, add allowlists and per-tool permissions so a compromised agent cannot turn into a self-propagating loader inside your environment.

That detail matters because a worm is malware designed to spread from one system to another, often without direct human help. By embedding an LLM directly inside the malware, the prototype can make use of AI features even on computers that are isolated, restricted, or otherwise unable to call out to an external model service.

Schneier said this is the closest example he has seen to John Brunner’s original 1975 conception of a computer worm, referring to the science fiction idea of malware that behaves more autonomously than traditional code. He linked the prototype to Brunner’s novel The Shockwave Rider, which has long been cited in discussions of self-propagating software.

The post does not describe the worm’s full capabilities or how it spreads, and it does not say the prototype has been deployed in the wild. But the core point is clear: researchers are now demonstrating malware that combines propagation techniques with on-device AI execution.

That combination could matter for defenders because it changes some assumptions about how malicious code may behave after infection. If the model travels with the malware, attackers may not need a live connection to an external AI provider to use language-based decision-making, adaptation, or content generation inside a compromised environment.

Schneier’s post is brief, but the framing is significant. He places the prototype in the malware category, ties it to prior reporting about AI-boosted worms, and highlights the unusual part: the model is part of the payload itself.

The post was published on June 5, 2026, and tagged under AI, malware, and science fiction.

Source: Schneier on Security ↗

More from Security News