Researchers developed Morris II, the first generative AI worm capable of stealing data and sending malicious emails. The malware spreads autonomously between systems by targeting AI-powered email assistants.
The worm uses adversarial self-replicating prompts to manipulate AI models into executing commands. This process allows the software to propagate itself without any human interaction.
Proof-of-concept tests successfully breached Google Gemini Pro and OpenAI ChatGPT 4.0 in controlled environments. The research identifies a new vulnerability class within interconnected AI agent ecosystems.