Rogue Agents Watch › Records › morris-ii-genai-worm
Morris II — self-replicating worm targeting GenAI-powered applications
Disclosed · added to the index · last updated
Grades
- Verification status
- Test / evaluation — Occurred in a controlled lab test, red-team exercise, or evaluation — not a real-world attack.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
Academic researchers (Stav Cohen, Ron Bitton, Ben Nassi) disclosed "Morris II" in March 2024 — a research proof-of-concept for the first worm designed to target generative-AI ecosystems. It uses an adversarial self-replicating prompt that, when processed by a GenAI model inside a retrieval-augmented email assistant, replicates itself into the model's output, drives a malicious action (such as exfiltrating confidential data), and propagates zero-click to other connected AI agents. Demonstrated in a controlled lab against GPT-4, Gemini Pro and LLaVA; never deployed in the wild.
Impact as stated
Research demonstration only: no real-world victims. Showed that a self- replicating prompt can exfiltrate confidential data and propagate between GenAI-powered email assistants without user interaction.
Facts as stated by sources
- Actor
- Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech) (Researcher)
- Category
- Lab escape / evaluation
- Models named
- GPT-4, Gemini Pro, LLaVA
- Model families
- GPT (OpenAI), Gemini (Google), Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Exfiltration, Impact
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0051.001, AML.T0057
Mitigations as stated
- The researchers proposed a detection guardrail ('Virtual Donkey') and disclosed to OpenAI and Google before publication.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Sources (3)
- Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
arXiv · Research paper · · archived copy - ComPromptMized — Here Comes the AI Worm
Cohen, Bitton, Nassi · First-party disclosure · archived copy - AI worm infects users via AI-enabled email clients — Morris II generative AI worm steals confidential data as it spreads
Tom's Hardware · News · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "morris-ii-genai-worm". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/morris-ii-genai-worm.json — CC BY-SA 4.0.