{ "actor": "Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech)", "actor_type": "researcher", "added": { "by": "MLSecOpsHub", "date": "2026-08-13" }, "ai_role": "load-bearing", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "lab-escape-eval", "confidence": "primary", "date_disclosed": "2024-03-05", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "morris-ii-genai-worm", "impact": "Research demonstration only: no real-world victims. Showed that a self- replicating prompt can exfiltrate confidential data and propagate between GenAI-powered email assistants without user interaction.", "last_updated": "2026-08-13", "lifecycle_phases": [ "initial-access", "execution", "exfiltration", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [ "AML.T0051.001", "AML.T0057" ], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "The researchers proposed a detection guardrail ('Virtual Donkey') and disclosed to OpenAI and Google before publication." ], "model_families": [ "openai-gpt", "gemini", "other" ], "models": [ "GPT-4", "Gemini Pro", "LLaVA" ], "name": "Morris II — self-replicating worm targeting GenAI-powered applications", "related": [], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20260909163233/https://arxiv.org/abs/2403.02817", "date": "2024-03-05", "publisher": "arXiv", "title": "Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications", "type": "research-paper", "url": "https://arxiv.org/abs/2403.02817" }, { "archive_url": "https://web.archive.org/web/20260708085943/https://sites.google.com/view/compromptmized", "publisher": "Cohen, Bitton, Nassi", "title": "ComPromptMized — Here Comes the AI Worm", "type": "first-party-disclosure", "url": "https://sites.google.com/view/compromptmized" }, { "archive_url": "https://web.archive.org/web/20260309084729/https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-worm-infects-users-via-ai-enabled-email-clients-morris-ii-generative-ai-worm-steals-confidential-data-as-it-spreads", "publisher": "Tom's Hardware", "title": "AI worm infects users via AI-enabled email clients — Morris II generative AI worm steals confidential data as it spreads", "type": "news", "url": "https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-worm-infects-users-via-ai-enabled-email-clients-morris-ii-generative-ai-worm-steals-confidential-data-as-it-spreads" } ], "status": "test-eval", "summary": "Academic researchers (Stav Cohen, Ron Bitton, Ben Nassi) disclosed \"Morris II\" in March 2024 — a research proof-of-concept for the first worm designed to target generative-AI ecosystems. It uses an adversarial self-replicating prompt that, when processed by a GenAI model inside a retrieval-augmented email assistant, replicates itself into the model's output, drives a malicious action (such as exfiltrating confidential data), and propagates zero-click to other connected AI agents. Demonstrated in a controlled lab against GPT-4, Gemini Pro and LLaVA; never deployed in the wild.", "targets": { "countries": [], "orgs_affected": null, "records_exfiltrated": null, "sectors": [] } }