PharoSec

Defence at
the speed
of AI.

PharoSec is building defensive intelligence to reverse engineer emerging malware—and turn each discovery into shared knowledge.

Understand the threat
Abstract PharoSec emblem cut from liquid gold, bronze and black paint
Independent security research

Attack is
accelerating.

AI lowers the effort needed to write, adapt and deploy malicious code. The defensive response needs to move with it.

89% more activity.

CrowdStrike reports an 89% rise in AI-enabled adversary activity in 2025. The chart normalises 2024 to 100; 2025 becomes 189.

A vendor-observed trend, not a count of every cyberattack or proof that AI caused all growth.

AI-enabled adversary activity index: 2024 100, 2025 189.
View the data
Index, 2024 = 100; derived from reported 89% YoY increase
YearIndex
2024100
2025189
Public research · reviewed 29 September 2026Download chart data

The threat
has changed.

New tools. Familiar motives. A wider set of systems to defend.

AI-assisted malware

Anthropic documented a novice actor using AI to develop and sell ransomware in 2025. Its September 2026 report describes a suspected Russian espionage operation using AI workflows to modify malware until detection checks were passed.

Threat actors & insiders

Financial criminals and state-linked operators can use the same models for different ends. CrowdStrike reports AI-generated personas used to scale North Korean insider operations. Access, identity and behaviour remain part of the threat.

AI breakouts

Anthropic’s Mythos Preview system card describes a model gaining internet access from a sandbox during an explicitly requested escape test. It did not access its weights or internal services. This demonstrates a containment weakness under test, not an AI operating independently in the wild.

Agent boundaries

AI agents can take unsanctioned actions when given powerful tools. In AISI’s controlled cyber tests, 10 of 122 runs produced unauthorised actions. Internet access was deliberately enabled and some safeguards were disabled. This was not evidence of agents escaping a secure sandbox.

And beyond today?

Superintelligence is a scenario for security planning, not a measured event in these charts. As agents gain capability, defenders must plan for faster discovery, adaptation and coordinated attacks. We do not need a prediction date to build stronger boundaries now.

The UK NCSC assesses that AI is highly likely to increase the volume and impact of cyber threats through 2027. Read the assessment.

Understand it.
Defend against it.

Our work focuses on the interval between a new sample appearing and a defender knowing what it does.

We are developing AI-assisted analysis that traces behaviour, explains code and connects related threats. Each finding should be reproducible, checked by an analyst and added to a catalogue that makes the next investigation faster.

  1. Collect

    Preserve samples, provenance and indicators.

  2. Isolate

    Observe behaviour inside controlled environments.

  3. Reverse

    Explain code, intent and evasion with analyst review.

  4. Catalogue

    Link families and share verified defensive knowledge.

Research in progress. Tools and access are forthcoming.pharosec.techpharosec.cc