Skynet is an experimental Windows malware sample identified in June 2025 that embeds a prompt-injection attempt intended to evade AI-assisted malware analysis. Its embedded instructions seek to override an analyzing model’s task and induce a false benign verdict. Testing against OpenAI o3 and GPT-4.1 found that both models resisted the injection and continued their analysis.
The sample combines rotating byte-wise XOR and Base64 obfuscation with anti-debugging and virtualization checks. Its environment checks examine hypervisor indicators, hardware information, environment variables, network adapter characteristics, and running processes. Opaque predicates complicate control-flow analysis. Skynet attempts to collect SSH-related information, including a private key, and local host-resolution data, but writes the collected contents to standard output rather than transmitting them. It also decrypts and launches an embedded Tor client with local proxy and control interfaces, then deletes its temporary working directory.
Skynet is a partially developed proof of concept rather than a demonstrated fully operational malware deployment. This 2025 sample is distinct from the older Tor-enabled, ZeuS-based Skynet botnet and the Skynet-branded DDoS service operated by Anonymous Sudan; their capabilities and attribution should not be conflated.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AnonSudan accepted orders over the instant messaging service Telegram, and marketed its DDoS service by several names, including “Skynet,” “InfraShutdown,” and the “Godzilla botnet.”
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Amazon said AnonSudan launched its attacks by finding hosting companies that would rent them small armies of servers.
Specifically, the warrants authorized the seizures of computer servers that launched and controlled the DDoS attacks, computer servers that relayed attack commands to a broader network of attack computers, and accounts containing the source code for the DDoS tools used by Anonymous Sudan.
Код обфусцирован побайтовым XOR с ротацией и 16-байтным хардкодированным ключом; payload дополнительно закодирован в base64.
The malware contains an encrypted embedded PE binary, which can be extracted. It will be written on the host, named skynet... The main uses XOR — with the same key — to decrypt an embedded binary... The result will be written to the filesystem, in a temporary directory, with name skynet.
В материале XOR/base64-обфускация отнесена к Obfuscated Files or Information (T1027) с элементами Command Obfuscation (T1027.010).
"resulting in the end with the core being disguised either as Internet Explorer or as svchost.exe"
Embedded in the C++ was an instruction addressed to whatever model came to analyze the file, telling it to ignore its previous instructions and report the binary as clean.
При запуске образец проверяет запуск из временной директории — индикатор sandbox-окружения; также описаны шесть функций антисандбокса.
Reads the registry (Hardware\Description\System\BIOS) and checks for specific BIOS vendor signatures... In the registry (System\CurrentControlSet\Services\disk\Enum), searches for specific names like VMware, VBOX or QEMU.
"Get information on the compromised computer !info, !version, !hardware, !idle"
«Сбор содержимого чувствительных директорий — результаты выводятся в stdout, но не эксфильтрируются».
При запуске образец проверяет запуск из временной директории — индикатор sandbox-окружения; также описаны шесть функций антисандбокса.
The malware may contact 2 different onion URLs: s4k4ceiapwwgcm3mkb6e4diqecpo7kvdnfr5gg7sph7jjppqkvwwqtyd.onion, port 8080 ... and zn4zbhx2kx4jtcqexhr5rdfsj4nrkiea4nhqbfvzrtssakjpvdby73qd.onion on port 31068.
«Расшифровка встроенного Tor-клиента, запуск прокси через CreateProcessA на указанных портах».
"it's requesting them to a proxy running locally... This proxy then translates the request to a specific Tor .onion pseudo-domain and tunnel the requests through the Tor SOCKS proxy"
Skynet was more like a “distributed cloud attack tool,” with a command and control (C2) server, and an entire fleet of cloud-based servers that forwards C2 instructions to an array of open proxy resolvers run by unaffiliated third parties, which then transmit the DDoS attack data to the victims.
"embeds the CGMiner... starts mining bitcoins only after two minutes of inactivity and immediately stops when some monitored event occurs"
Anonymous Sudan ... is a cybercrime business known for launching powerful distributed denial-of-service (DDoS) attacks against a range of targets, including dozens of hospitals, news websites and cloud providers.
CrowdStrike said the success of AnonSudan’s DDoS attacks stemmed from a combination of factors, including sophisticated techniques for bypassing DDoS mitigation services. Also, AnonSudan typically launched so-called “Layer 7” attacks that sought to overwhelm targeted “API endpoints” ... with bogus requests for data, leaving the target unable to serve legitimate visitors.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Incomplete proof-of-concept malware sample that uses XOR/Base64 obfuscation, anti-debugging and sandbox-evasion checks, collects contents of sensitive directories to stdout, decrypts and launches an embedded Tor client/proxy, and removes its temporary directory. Its distinguishing feature is an embedded prompt-injection string intended to manipulate LLM-based malware-analysis tools into reporting that no malware was detected.
A malware sample containing embedded prompt-injection instructions intended to mislead AI-based malware analysis systems into reporting the binary as clean.
Malware that attempts to evade analysis and detection through sandbox evasion and prompt-injection text loaded into memory before its main payload. The report notes that the prompt-injection technique is not yet effective against updated AI models. Its main payload’s functionality is not specified.
Skynet is a malware strain designed to test prompt injection against AI-powered malware analysis systems. It embeds malicious instructions intended to manipulate LLM-based security tools into misclassifying the sample as benign, though researchers described it as an experimental proof-of-concept rather than a fully functional threat deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.