Agentic AI Empowers Solo Cybercriminals to Rapidly Develop Advanced Malware

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

In early 2026, cybercriminals leveraged agentic AI systems to autonomously create advanced malware, such as VoidLink, in days rather than months. This shift, highlighted by Check Point Software, has enabled individuals to execute complex cyberattacks, significantly increasing cybersecurity risks and reducing barriers to cybercrime.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the use of agentic AI systems to develop malware and automate cyberattack tasks, which directly leads to harm by enabling more rapid and sophisticated cyberattacks. The harms include increased cybercrime activity, data exposure, and security risks to organizations, fulfilling the criteria for harm to communities and property. The AI system's use is central to the incident, not merely potential or speculative, and the article describes ongoing impacts and risks. Hence, this is an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital security

Affected stakeholders
BusinessGeneral public

Harm types
Economic/PropertyPublic interest

AI system task:
Content generationReasoning with knowledge structures/planning


Articles about this incident or hazard