Abstract
Malware is currently detected using predominantly static analysis techniques such as rule- and signature-based frameworks. Their effectiveness is largely due to attackers reusing well-known components and toolchains to lower skill requirements, reduce development effort and time to deployment. As a result, malware exhibits recognizable structural patterns that static detectors can reliably identify. The increasing availability of AI-assisted coding tools challenges this assumption by enabling and emboldening attackers to generate malicious software from scratch, producing samples with highly variable code structures but identical malicious intent. In this work, we demonstrate that AI-generated malware permutations can evade static analysis, while their runtime behavior remains largely invariant. We focus our work on malicious shell scripts as a specific class of malware. Such malicious shell scripts are commonly used in attacks against Linux based IoT devices such as routers, cameras, and smart home devices. Our experimental results show that dynamic and behavioral analysis techniques are more robust in this context, highlighting the need to lessen the prevailing dependency on static analysis and instead shift malware detection strategies for systems toward behavior-centric approaches.
| Original language | English (Ireland) |
|---|---|
| Title of host publication | Proceedings of the 23rd ACM International Conference on Computing Frontiers (CF Companion ’26 ) |
| Publisher | Association for Computing Machinery (ACM) |
| Pages | 1-8 |
| Number of pages | 8 |
| ISBN (Electronic) | 979-8-4007-2568-5 |
| DOIs | |
| Publication status | Published - 27 Jun 2026 |
UCC Futures
- Future of Networks, Systems & Cybersecurity
- Artificial Intelligence and Data Analytics
Keywords
- Malware
- Security
- Privacy
- [ComputerScience]
Fingerprint
Dive into the research topics of 'Detecting vibe-coded malware'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver