
Researchers from the University of Toronto, Vector Institute, the University of Cambridge, and ServiceNow have cooked up a computer worm powered by an open-weight large language model. It scans a network, identifies vulnerabilities on target machines, generates an attack plan, and — once a device is compromised — copies itself over to start hunting for the next victim. No human in the loop.
The team tested the worm in an isolated network of 33 virtual machines across 15 rounds, each lasting seven days. On average, the worm grabbed admin privileges on 23.1 machines and launched fresh copies on 20.4 of them, with the longest continuous infection chain stretching seven generations.
Unlike a conventional worm that runs through pre-scripted attack routines, this one adapts to each machine it encounters. It also gobbles up vulnerability disclosures published after the model finished training, and turns those written advisories into actual attack steps.
Before you start panic-updating your firewall: this is still a lab proof of concept. Every machine in the test network was deliberately seeded with vulnerabilities, and there was no antivirus or active defense to stop the worm. The main experiments also leaned on a shared GPU pool, and neither the model nor the full code has been released. The paper is up on arXiv.