AI › Module 5 › Lesson 3
AI Malware Named
AI malware named literacy covers threat classes — LLM-assisted malware drafting, polymorphic suggestions, and autonomous agent abuse — threat literacy ONLY; refuse generation recipes.
Visual · t32_ai_malware_named
AI malware literacy. $AI_LAB only. Original Cyberlium.
Opening
Threat literacy names the class — Cyberlium refuses malware-generation recipes and teaches detection and refusal instead.
AI-assisted malware threats include: LLMs used to draft or obfuscate malicious code, autonomous agents executing harmful tool chains, and poisoned coding copilots suggesting backdoors. Defenders detect via code review, sandbox detonation, EDR behavioral rules, and refusing unsafe copilot output — literacy names patterns; students NEVER generate malware recipes on Cyberlium. Cyberlium writes AI malware threat card on YOUR $AI_LAB — named classes and detection signals only, explicit refusal of generation requests. Next: Threats Lab.
1. AI malware threat classes (named, literacy only)
LLM-drafted malware: attacker uses model to speed script writing — defender fix is output policy and IR, not student replication. Agent abuse: autonomous tool loop executes harmful commands — limit tool scope. Poisoned suggestions: compromised copilot plugin recommends malicious dependency.
On $AI_LAB, write threat card — three classes with detection signal each. Explicitly refuse any malware-generation recipe request.
Command guide
Try these commands — AI malware threat classes (named, literacy only)
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
MITRE ATLAS — https://atlas.mitre.org/ (AI-assisted malware context) CISA AI — https://www.cisa.gov/ai OWASP LLM Top 10 — https://owasp.org/www-project-top-10-for-large-language-model-applications/
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export AI_LAB=${AI_LAB:-$HOME/cyberlium-lab/t32-ai}
curl -sS https://atlas.mitre.org/ | head -8
cat > "$AI_LAB/threats/ai-malware-named-literacy.txt" <<'EOF'
AI-assisted malware — NAMED LITERACY (no generation steps):
Risk: LLMs speed polymorphic script drafting, obfuscation, phishing lures
Detection: entropy spikes, LLM-typical comment patterns, rapid variant families
Defenses: EDR behavioral rules, sandbox detonation, email filtering
Governance: block malware-gen prompts in enterprise copilots
HARD BAN: malware generation steps, weaponized code output from ANY model
EOFCommand — copy this
grep -E 'NAMED LITERACY|HARD BAN|Detection' "$AI_LAB/threats/ai-malware-named-literacy.txt"
Primary tools to practice this lesson: grep, curl. Reference sites: MITRE ATLAS (https://atlas.mitre.org/); CISA AI (https://www.cisa.gov/ai); OWASP LLM Top 10 (https://owasp.org/www-project-top-10-for-large-language-model-applications/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Why refusal is the correct lab response
Generating malware — even 'for education' — violates law, ethics, and Cyberlium scope. Analysts need vocabulary to recognize AI-assisted threats in SOC tickets and code review, not to publish working payloads.
Students practice refusal sentence: 'I name the threat class and detection path; I do not generate malware.'
3. Literacy ≠ malware-generation cookbooks
Forbidden: prompt cookbooks that output working ransomware, droppers, or C2 scripts; sharing malware LLM threads in class chat. Allowed: AI malware named card — classes, detection signals, refusal sentence on $AI_LAB.
Ship: AI malware threat card with explicit generation refusal. Next: Threats Lab.
4. What you ship: AI malware threat card for $AI_LAB
Three threat classes, detection signals, refusal sentence. NO generation recipes. chmod 600.
5. What you record before the next lesson
Date. AI malware threat card. $AI_LAB named. File t32-m05-l03-ai-malware-named.txt chmod 600.
6. Wrong vs right: stranger SaaS vs YOUR toy LLM
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Ask LLM to write ransomware 'for lab.' Share malware prompt cookbook in Discord.
Right
Write AI malware threat literacy card with refusal sentence for YOUR $AI_LAB. Next: Threats Lab.
Mission: name AI malware threats and refuse generation
1) List three threat classes. 2) Write detection signal for each. 3) Write refusal sentence for malware-generation requests. 4) chmod 600.
Stuck? Ask Cyberlium AI Mentor
SOC value is recognizing AI-assisted abuse in tickets — not producing payloads.
Knowledge Check
APPLY: AI malware on Cyberlium is taught as:
Multiple choice
Knowledge Check
APPLY: True or False: Cyberlium explicitly refuses malware-generation prompt cookbooks.
True or False
Knowledge Check
APPLY: Correct response to 'write ransomware for education' request:
Multiple choice