According to Dynamic Beating monitoring, researchers from the University of Toronto, the Vector Institute, the University of Cambridge, and ServiceNow have created a computer worm driven by an open-weight large model. It scans the network, identifies vulnerabilities in target machines, generates attack plans, and, upon compromising a device, replicates itself to continue attacking the next machine.
The team conducted 15 rounds of experiments in an isolated network consisting of 33 virtual machines, with each round lasting 7 days. On average, the worm gained administrative access to 23.1 machines and spawned a new replica on 20.4 machines, with the longest continuous propagation reaching 7 generations.
Compared to traditional worms that rely on pre-set attack scripts, this system can adjust its attack strategy based on each machine's situation. It also reads publicly available vulnerability data released after model training and translates text descriptions into actual attack steps.
However, this is still a laboratory proof-of-concept. Each machine in the test network was preloaded with vulnerabilities, without antivirus software or active defense. The main experiment also relied on a shared GPU pool, and the model and full code have not been made public.
