Rogue Agents Watch › Records › morris-ii-genai-worm

Morris II — self-replicating worm targeting GenAI-powered applications

Disclosed · added to the index · last updated

Grades

Verification status
Test / evaluation — Occurred in a controlled lab test, red-team exercise, or evaluation — not a real-world attack.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Medium — Limited or contained harm, or high-signal capability demonstration.

Summary

Academic researchers (Stav Cohen, Ron Bitton, Ben Nassi) disclosed "Morris II" in March 2024 — a research proof-of-concept for the first worm designed to target generative-AI ecosystems. It uses an adversarial self-replicating prompt that, when processed by a GenAI model inside a retrieval-augmented email assistant, replicates itself into the model's output, drives a malicious action (such as exfiltrating confidential data), and propagates zero-click to other connected AI agents. Demonstrated in a controlled lab against GPT-4, Gemini Pro and LLaVA; never deployed in the wild.

Impact as stated

Research demonstration only: no real-world victims. Showed that a self- replicating prompt can exfiltrate confidential data and propagate between GenAI-powered email assistants without user interaction.

Facts as stated by sources

Actor
Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech) (Researcher)
Category
Lab escape / evaluation
Models named
GPT-4, Gemini Pro, LLaVA
Model families
GPT (OpenAI), Gemini (Google), Other / unspecified
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Execution, Exfiltration, Impact
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0051.001, AML.T0057

Mitigations as stated

  • The researchers proposed a detection guardrail ('Virtual Donkey') and disclosed to OpenAI and Google before publication.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Sources (3)

  1. Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
    arXiv · Research paper · · archived copy
  2. ComPromptMized — Here Comes the AI Worm
    Cohen, Bitton, Nassi · First-party disclosure · archived copy
  3. AI worm infects users via AI-enabled email clients — Morris II generative AI worm steals confidential data as it spreads
    Tom's Hardware · News · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "morris-ii-genai-worm". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/morris-ii-genai-worm.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction