Polymorphic Viruses and Artificial Intelligence: How AI Is Changing Cyber Threats

Artificial intelligence is already helping businesses automate tasks, analyze information faster and improve efficiency. But businesses are obviously not the only ones taking advantage of these new capabilities.

Cybercriminals are using them too.

AI can help attackers create more convincing phishing campaigns, look for vulnerabilities, gather information about their targets or accelerate malware development. One development deserves particular attention: the use of AI to create polymorphic viruses and other types of malware that can modify their code to make detection more difficult.

The concept itself is not new. Polymorphic malware has been around for a long time. What AI changes is primarily the speed and ease with which some of these techniques can now evolve.

What Is a Polymorphic Virus?

A polymorphic virus is a type of malware that can modify certain characteristics of its code without changing what it is designed to do.

Think of a burglar who changes their appearance every time they try to break into a building. The objective remains the same, but recognizing them becomes more difficult.

In cybersecurity, this ability can be used to change a piece of malware’s digital signature. This matters because some traditional detection methods rely on recognizing signatures associated with known threats.

Polymorphism therefore allows the same malware to appear in different forms. Artificial intelligence did not invent this technique. It has existed for decades.

AI, however, can make the process faster and more automated.

How Is Artificial Intelligence Changing Malware?

Until recently, when we talked about cybercriminals using AI, we were mostly referring to relatively straightforward applications: writing phishing emails, translating messages, conducting research or getting help with programming.

We’re now beginning to see something different.

In 2025, Google Threat Intelligence Group documented experimental malware that used AI models directly during execution. One example, called PROMPTFLUX, was designed to communicate with an AI model to obtain new techniques for modifying and obfuscating its code.

It’s important to keep this in perspective. At the time, Google specified that the malware was still under development and, in the form observed by its researchers, was not capable of compromising a device.

Still, the experiment gives us an indication of where some cyber threats could be heading.

In 2026, Google also reported that malicious actors were experimenting with AI to accelerate the development of polymorphic malware and generate code designed to make detection more difficult.

This doesn’t mean we’re suddenly facing autonomous viruses that are impossible to stop. The issue is much more practical: AI allows attackers to automate certain tasks and work faster.

Cyberattacks and AI: Speed Is the Real Change

This is probably where the biggest concern lies for businesses.

Cybercriminals didn’t wait for artificial intelligence to search for vulnerabilities, send fraudulent emails or develop malware. They were already doing all of that.

AI simply allows them to do more, faster.

A phishing campaign can be adapted for different targets. Information about a company can be analyzed more easily. Code can be generated or modified faster. Tasks that once required considerable time and effort can now be accelerated.

In the case of polymorphic malware, this could make it easier to produce multiple variations of the same threat.

And when a threat can continually change its appearance, simply looking for a file that has already been identified as malicious is no longer enough.

How Can a Polymorphic Virus Be Detected?

For years, a large part of antivirus protection was based on a relatively simple principle: once malware was discovered, its signature could be added to security databases so that it could be recognized the next time it appeared.

That approach is still useful, but it can no longer be the only line of defence.

Modern cybersecurity solutions also look at what is actually happening within an IT environment.

Has a device suddenly started communicating with an unusual destination? Is an account attempting to access resources it doesn’t normally use? Is an application modifying a large number of files within seconds?

Even if the malware responsible has never been seen in exactly that form before, its behaviour can reveal that something isn’t right.

This is one of the roles of detection and response solutions such as EDR and XDR.

As cyber threats become capable of evolving more quickly, this type of behavioural detection becomes increasingly important.

Is Antivirus Still Enough to Protect Your Business?

No, but that doesn’t mean antivirus is no longer useful.

Antivirus remains an important part of a company’s security. The problem arises when it represents almost the entire cybersecurity strategy.

Today, effective protection depends on several layers working together.

Multi-factor authentication and proper access management can help limit the impact of compromised credentials. Updates and patch management reduce the number of vulnerabilities attackers can exploit. Continuous monitoring makes it easier to identify unusual activity quickly, while backups provide another layer of protection when an incident does occur.

And employees can’t be overlooked.

AI can also be used to create fraudulent communications that are much more convincing than they used to be. The obvious spelling mistakes and awkward wording that once made some phishing emails easy to recognize aren’t always there anymore.

Cybersecurity awareness therefore remains essential.

Artificial Intelligence Is Also Strengthening Cybersecurity

It would be misleading to present artificial intelligence only as a new tool for cybercriminals.

Cybersecurity teams are using it too.

AI can help analyze enormous volumes of signals, identify unusual behaviour and accelerate incident analysis. It can also help cybersecurity specialists make connections between different activities that would be much more difficult to identify manually.

In June 2026, for example, Microsoft reported using AI as part of an operation targeting cybercriminal infrastructure. AI-assisted analysis accelerated the investigation of malware and helped identify connections between different infrastructures, contributing to the disruption of more than 200 command-and-control servers.

The tools are evolving on both sides.

And that’s probably the best way to look at what is happening today: AI isn’t changing the fundamentals of cybersecurity, but it is dramatically accelerating the game.

How Can You Protect Your Business Against AI-Driven Cyber Threats?

Polymorphic viruses existed before AI. So did phishing, vulnerability exploitation and credential theft.

What is changing is the ability of cybercriminals to automate certain tasks, adapt their methods and operate more quickly.

For businesses, the answer isn’t to look for a new solution that promises to stop every “AI-powered attack.” It starts with making sure the foundations of their cybersecurity strategy are solid.

Are access rights properly controlled? Are systems up to date? Are devices being monitored? Can unusual behaviour be detected quickly? Do employees know how to recognize a fraudulent request that looks completely legitimate? And, perhaps most importantly, would the organization know what to do tomorrow morning if an attack succeeded despite its protections?

These questions were already important. With AI, they’re becoming even more so.

Want to know whether your IT environment is adequately protected against today’s cyber threats? Kezber’s experts can help you assess your current situation, identify your main risks and determine which measures to prioritize to better protect your business. Contact our team today!