People still seem to think AI is too sloppy, locked down, or dumb to be much use to attackers.
IBM’s latest analysis pushes back on that pretty quickly.
The company recently published a breakdown of a likely AI-generated backdoor used in a ransomware case linked to Hive0163 and Interlock. The script itself was not especially sophisticated. IBM described it as more functional than impressive. Still, it was deployed inside a live operation and used to help maintain access to a compromised server for more than a week.
That is where this gets interesting.
The point is not that AI has suddenly started producing elite malware. It’s that even low grade output can still be useful in the hands of an attacker who already knows what they’re trying to achieve.
IBM found it in a ransomware case
According to IBM X-Force, the malware they named ‘Slopoly’ appeared during a ransomware engagement and showed several signs of LLM-assisted development.
It was a PowerShell backdoor. It beaconed home, accepted commands, executed them through cmd.exe and helped the operator hold access.
There’s nothing special about it. That’s part of the point.
We may now be entering a phase where AI doesn’t need to produce highly advanced malware to make a meaningful difference. It only needs to help attackers produce usable tooling faster.

Redacted excerpt of the Slopoly script analysed by IBM X-Force. The code shows the kind of structured comments and naming conventions often associated with LLM-assisted output.
The malware was basic but still useful
A lot of people still seem to think the AI threat only becomes serious once the malware looks polished or technically impressive.
But attackers don’t need perfect malware. They need cheap malware that works.
If a script can maintain persistence, run commands, call back to infrastructure, and buy more time inside a compromised environment, it has already done enough to justify its existence.
That is what makes the IBM case worth paying attention to.
AI is lowering the cost of attack tooling
The bigger issue here is not one PowerShell script with a ‘Slopoly’ name.
It’s what this says about attacker economics.
If AI can help produce serviceable backdoors, support scripts, loaders, or operational utilities faster than before, then the barrier to building usable tooling starts to drop. That doesn’t mean every attacker suddenly becomes highly capable. It means more attackers can produce more material, faster, and with less effort.
It can mean faster experimentation. More disposable malware. More one-off, highly targeted variants. More noise for cyber experts to sort through. It also makes attribution harder over time, especially if scripts are being rebuilt, adjusted, and swapped out quickly rather than maintained as stable malware families.
That’s before you even get to the more advanced possibilities.
Right now, the immediate concern is not AI replacing threat actors. It is AI making existing operators more efficient.

IBM X-Force infection chain from the Slopoly ransomware case.
What this changes for defenders
The safest mistake defenders can avoid here is assuming low quality means low risk.
A basic backdoor can still support a serious intrusion if it lands in the right environment and stays there long enough. It can still create room for later movement, support data theft, and help an attacker keep their place while the operation progresses.
The lesson from IBM’s analysis isn’t that AI-generated malware is suddenly advanced.
It’s that it doesn’t need to be.



