First per-app firewall that catches AI-powered worms
AI-augmented malware now queries commercial LLMs such as ChatGPT, Claude, and Gemini during live attacks to generate reconnaissance commands and evade detection. NetInsightPro identifies non-browser processes making LLM API calls, flags autonomous lateral movement immediately after an LLM response, and escalates when the same threat pattern spreads across multiple hosts in your network.
Available on Pro and Enterprise tiers. AI-threat detection and telemetry now live.
From lab to confirmed deployment
AI-augmented malware crossed from theoretical research into confirmed state-sponsored use in 2025. CrowdStrike documented an 89% surge in AI-enabled adversary operations in their 2026 Global Threat Report.[5]
First demonstrated self-replicating worm targeting GenAI ecosystems. Exploited RAG database poisoning and adversarial prompt embedding to propagate across ChatGPT-4, Gemini Pro, and LLaVA.
First confirmed in-the-wild malware that queries a live LLM (Hugging Face, Qwen2.5) during active attacks to generate Windows reconnaissance commands, then exfiltrates documents via SSH to attacker C2.
Backdoor using the OpenAI Assistants API as its C2 channel. A .NET DLL polls an attacker-controlled OpenAI account for encrypted commands — traffic is standard HTTPS to api.openai.com, indistinguishable from legitimate developer use by TLS inspection.
What our detection catches
NetInsightPro's per-app egress telemetry creates a detection surface traditional tools don't have — behavioural signals that reveal AI-era attacks without ever inspecting a prompt.
LLM/API egress from non-browser processes
Alerts when a process outside your allowlist reaches out to LLM and AI API endpoints. A non-developer process talking to an AI service is the foundational indicator for both LLM-as-C2 and LLM-assisted reconnaissance.
Malware disguises exfiltration as ordinary traffic to a legitimate AI API. Because detection is per-app, NetInsightPro sees the call come from a process that has no reason to talk to an LLM — a signal TLS inspection and traditional firewalls miss entirely.
LLM-assisted lateral movement
Flags abnormal process-spawn and outbound-connection behaviour that follows an LLM response — the signature of LLM-orchestrated reconnaissance, where malware acts on model-generated commands and immediately attempts to move laterally.
Malware asks a live model for its next step, then immediately probes a neighbouring host. NetInsightPro links the AI response to the follow-up intrusion within seconds — catching the attack while there is still one machine to contain, not a network to rebuild.
Cross-host worm replication
Escalates when a novel binary begins making AI API calls across multiple devices in your tenant — the clearest signal of worm propagation, an unrecognised executable spreading host to host and calling out to AI services.
One infected workstation starts seeding an unknown binary across the fleet. NetInsightPro correlates the new binary calling AI APIs on host after host and escalates within minutes — the security team isolates the source before the worm becomes an incident.
Detection without reading your prompts.
AI threat detection works at the network metadata layer. NetInsightPro never sees prompt text or LLM response content. Detection is based entirely on behavioral signals: which process is connecting, to which endpoint, at what interval, and at what byte volume.
Payload entropy capture is opt-in per-tenant and off by default. Every tenant can opt out entirely from AI threat telemetry via a single configuration setting.
- No raw prompt text or LLM response content is ever stored, logged, or transmitted — only network metadata (endpoint hostnames, byte counts, timing intervals)
- Process metadata is limited to process name and a one-way lineage hash — full command-line arguments are explicitly excluded
- Payload entropy capture is opt-in per-tenant, default off
- Per-tenant opt-out: configuration key ai_threat_telemetry_enabled (default on) — when set to false, no AI threat heuristic events are collected or stored
- No cross-tenant aggregation of threat data — correlation runs within the tenant stack only
- GDPR Art. 5 data minimisation and storage limitation: AI threat anomaly records retained 90 days, consistent with existing anomaly records
Where your data goes is a control, not a footnote.
Shadow-AI tools can route prompts — and the data inside them — to AI services operating in jurisdictions whose local laws, data-access powers, and reciprocal protections differ from your own. For defence, government, and regulated sectors, where an AI endpoint operates is a data-residency, exfiltration, and compliance question in one. NetInsightPro classifies AI traffic by the endpoint it reaches — 58 AI providers (63 host signatures) and counting — and labels each endpoint's operating jurisdiction, so egress is visible and reviewable, not blended into ordinary encrypted traffic. Jurisdiction is a fact we surface for every endpoint equally — what warrants elevated review is your policy to set, not ours.
The AI endpoints below are classified today, each labelled with its operating jurisdiction. Every classified endpoint surfaces as a named, categorised event with its jurisdiction shown — the same treatment for every territory, so you can see where your AI traffic goes and apply your own review policy.
Classifier coverage keeps growing across cloud LLM APIs, third-party inference platforms, coding assistants, local runtimes, and agent frameworks — surfaced here so security teams can see which jurisdictions their shadow-AI traffic reaches.
- Every jurisdiction sets its own rules on lawful access to data held there — and on whether foreign data receives reciprocal protection; where your AI traffic lands decides which rules apply
- Prompts frequently carry source code, credentials, customer records, and internal documents — the exact material a data-sovereignty policy is meant to keep in-territory
- Traditional firewalls see only ordinary HTTPS to a well-known domain; per-app classification names the destination and the jurisdiction
- For defence, government, and regulated sectors, egress to a jurisdiction your compliance regime treats as out-of-bounds can breach data-residency, export-control, and procurement obligations — which jurisdictions those are is yours to define
NetInsightPro attaches an operating jurisdiction to every AI endpoint it classifies and surfaces it the same way for all of them — an endpoint in your own country and one on the far side of the world carry the same field, shown identically. Jurisdiction is a neutral fact — NetInsightPro does not rank, flag, or pre-judge any country or provider by default.
Your compliance team chooses which jurisdictions warrant elevated review and configures it per tenant. By default nothing is elevated — the judgement is yours to make against your own regulatory regime, not ours to make for you.
These endpoints are classified today across 58 AI providers in total. Classification identifies the destination and jurisdiction from network metadata — it never reads prompt or response content. This is data-sovereignty visibility, not accusation.
Included on Pro and Enterprise.
Pro
Early Access- LLM/API egress alerting on your device
- Post-LLM lateral movement detection
- Cross-host worm-replication signal
- Per-tenant opt-out available
- AI threat telemetry in your device flow history
Enterprise
Early Access- Everything in Pro
- Cross-host worm signal across your fleet
- AI-threat detections viewable in the app and retained in your tenant backend; tenant-admin console visibility expanding
- SIEM forwarding of ai_category threat values (OCSF)
Detection is live and protecting you today.
Live and protecting you today
LiveDetection and the telemetry behind it are running in production right now — catching AI-era attacks that firewalls and traditional EDR wave straight through.
Stops your secrets leaving for an unknown AI
The moment a process that has no business talking to an AI service starts streaming data to one, NetInsightPro flags it — before your code, credentials, or clipboard leave the device.
A browser extension a developer trusted quietly begins piping clipboard contents to an unfamiliar AI endpoint. NetInsightPro catches the anomalous outbound call from a non-browser process the instant it starts — the exfiltration is cut off before a single line of proprietary code leaves the laptop.
Catches an attack the second it tries to spread
AI-assisted malware asks a live model for its next move, then pivots. NetInsightPro links the AI call to the follow-up intrusion attempt and raises the alarm in the narrow window where containment still works.
Malware on a workstation queries an AI model for reconnaissance commands, then tries to jump to a neighbouring machine over SSH. NetInsightPro ties the lateral move to the AI response within seconds and alerts before the attacker gains a second foothold.
Contains a worm before it owns your fleet
When one machine's malicious binary starts appearing across others, NetInsightPro correlates the spread fleet-wide and surfaces the worm signal in minutes — giving the security team time to isolate, not just investigate.
A single compromised workstation begins replicating a never-before-seen binary to other hosts, each phoning an AI API for instructions. NetInsightPro escalates the cross-host replication within minutes; the team quarantines the origin machine before the worm reaches the wider network.
Turns invisible AI abuse into a named, recorded signal
Every AI-threat detection is classified and written to your tenant's flow record — so an AI-era attack is captured as a clear, categorised event instead of blending into ordinary encrypted traffic. Analyst-facing views of these events are expanding.
A finance workstation that no one authorised to use AI tooling starts making AI-endpoint calls. Traditional firewalls see only ordinary HTTPS to a well-known domain; NetInsightPro names the behaviour and records it as a categorised AI-threat event — so the investigation starts with an answer instead of a hunch.
Keeps the evidence, wherever your people are
Detected events sync to a secure cloud backend, so remote and roaming devices stay covered and every AI-threat signal is retained for review — no on-prem collector, no gaps when someone works from home.
A laptop triggers an AI-egress detection on hotel Wi-Fi, far from the corporate network. The event still reaches your tenant backend, timestamped and attributed, and is retained for review as customer-facing access rolls out.
References
- Cohen, S., Bitton, R., Nassi, B. "Here Comes the AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications." arXiv:2403.02817, March 2024 (revised January 2025). Cornell Tech.
- CERT-UA / Splunk Threat Research. "LAMEHUG's LLM-Driven Cyber Intrusion." Splunk Security Blog, July 2025.
- Google Threat Intelligence Group (GTIG). "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools." Google Cloud Blog, 2025. Covers PROMPTSTEAL, PROMPTFLUX, APT28 attribution.
- Microsoft Security Blog. "SesameOp: Novel backdoor uses OpenAI Assistants API for command and control." November 3, 2025.
- CrowdStrike. "2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface." February 2026.
Talk to us about AI-worm detection.
Tell us your fleet size, SIEM, and IdP. We will walk you through how detection works and how it fits your environment. No spam. One business day turnaround.
Pro and Enterprise tiers · Early access · AI-threat detection live