Blue arrow pointing left.
Blog
September 17, 2026
RDAi™ System
Industry Insights
OT, IT, & IoT Security

The Evolving Cyber War: Artificial Intelligence Enters the Fray

AI-generated malware has transformed cyberwarfare, exposing the failure of rearward-looking defenses. Learn why delayed detection, dwell time, and security theater put critical systems at risk.

For as long as humans have waged wars, one pattern has, with tragic consistency, repeated itself: The next war is almost never fought the way the last one was. Yet, most armies almost always prepare for the past.  

They prepare for the previous war, for the types of wars. They prepare for the weapons and the strategies that they have already seen. Rare is it for a military to prepare for the wars that are coming. However, when a military does prepare for the future, it is usually extremely successful. 

History is littered with instructive examples. Thick-walled fortifications were rendered irrelevant by artillery and airpower. Trenches built to survive massed infantry charges were easily overrun by motorized armor and airborne divisions. Entire doctrines, once thought unassailable, collapsed because they were rooted in assumptions and tactics that no longer applied. 

Cybersecurity is no different. Today, we are already engaged in the next generation of cyberwarfare. Artificial Intelligence (AI) - generated malware and AI-based cybersecurity systems have entered the fray. The mindsets and the assumptions of previous cybersecurity strategies no longer apply. The cybersecurity landscape has fundamentally and forever been changed. 

In order to understand this fundamental change, let us consider the following: 

  • The General Inability to Detect Malware 
  • AI-generated Malware – The “Industrialization” of Malware 
  • The Myth of AI-Enhanced Malware Detection 
  • How to Fight the Emerging Cyber War 
  • The Way Forward for Malware Detection 
  • The Why of RDAi™ 

The General Inability to Detect Malware 

The current generation of cybersecurity systems seem to overflow with exuberant confidence in its own efficacy. Dashboards glow reassuringly. Vendors promise comprehensive protection. Executives are told that advanced tools powered by AI are watching everything and stopping threats before damage occurs.  

There is, unfortunately, a strong component here of “security theater,” a false sense of complacency created by a soap bubble of hype, technobabble, and steel doors protecting straw houses. Despite strong vendor claims, all independent studies paint a very different, and far less rosy picture. 

For as long as warfare has existed, defenders who rely upon security theater and who are lulled into a false sense of security eventually pay the price. Cyberwarfare is no different. The battlefield is modern and digital, but the principles predate ancient history. Even before the advent of AI-Generated malware, most cybersecurity systems struggled to detect even half of all malware attacks; attacks crafted by criminal artisans of various levels of creativity.  

Although attacks that had been previously documented and attacks “similar” to attacks previously documented could usually be effectively detected, attacks that were new and innovative slipped right through most defenses.  

In the realm of Operational Technology (OT), a realm in which most cybersecurity systems cannot operate at all due to the resource constraints of the devices that need protecting, the detection rates were much worse. It is a sad fact that if the detection system is not operating inside the device, effective detection is not possible. 

Despite the calming claims of many cybersecurity vendors, it is intuitively obvious that “if you can’t detect, you can’t protect.” And yet, an inability to detect malware attacks has plagued the cybersecurity industry for years, a condition exacerbated by the complacency inducing claims of the cybersecurity industry. 

AI-Generated Malware - The “Industrialization” of Malware 

The inability to effectively detect malware was a problem even before the recent explosive growth of sophisticated AI systems. Due to the emergence of AI-generated malware, the malware detection challenge is growing exponentially. Consider some of the reasons why. 

Malware creation has now outgrown the age of the artisan criminal and entered the “industrial” age of “machine-produced” malware. What was once the domain of skilled specialists is now automated.  

Generative AI systems can produce vast numbers of unique malware variants, each distinct, each different, each capable of bypassing defenses that rely on recognition, similarity, and/or prior knowledge. They can generate attacks against the tiny systems that comprise the critical infrastructure. The OT environment was once one that required sophisticated and highly specialized knowledge to penetrate. However, for today’s malicious AI systems, that arcane knowledge is readily available. 

The sheer variety of attacks combined with the rapidity with which they can be generated can easily overwhelm existing cyber-defenses.  

Think of a traditional anti-aircraft battery that was designed to defend against a few airplanes. All of sudden it is confronted with a massive array of hundreds, or even thousands, of attack drones. The anti-aircraft unit would have no chance. Its antiquated abilities would be totally negated by the newer technology’s superior capabilities for massive numbers and innovative tactics.  

Today’s cyber-attackers can generate more attacks and more attack variations in minutes than traditional defenders are able to analyze in months.  

For these new, AI-supported attackers, multiple failures are cheap, a small price to pay for ultimate victory. For the defenders, every failure is potentially catastrophic. This asymmetry, combined with the weapons technology gap, defines the cyberwar in which we are now engaged. 

The Myth of AI-Enhanced Attack Detection 

In response to the new AI-generated threats, the cybersecurity industry has offered a familiar solution: More artificial intelligence. 

The logic seems intuitive. If attackers use AI, defenders should use better AI. However, as seductive as this strategy is, it is also dangerously flawed.  

Artificial Intelligence is a tool, albeit an extremely powerful tool; and as with any tool, to be used effectively, it must be used appropriately. In this age of AI emergence, the old saw that says, “To a man with a hammer, everything looks like a nail,” is especially true.  

Yes, AI has its place in cyber defenses, but it must be applied with intelligence, and not as a universal panacea.  

Specifically, AI is excellent for analyzing attack patterns and drawing inferences about the attackers. It is very poor at detecting attacks. Why? 

It must be remembered that any AI tools available to defenders are also available to attackers.  It must also be remembered that often the attackers have far more resources, far fewer constraints, and a far greater tolerance for failure.  

For every AI detection algorithm the defenders develop, the attackers’ AI can develop AI-based evasive techniques. This pattern quickly devolves into an endless arms race, an arms race where both sides continue to escalate AI capabilities.  

However, it is a very uneven arms race. It favors the side that can afford endless experimentation and almost limitless losses. The enemy can afford to lose countless battles io win only one. We, the defenders, cannot afford to lose even one.

Most AI-driven detection systems infer maliciousness from patterns, behaviors, and deviations from learned norms. This inevitably produces false positives and blind spots. Worse still, it creates potentially fatal response time delays. Due to the sheer number of alerts generated by probabilistic algorithms, all alerts must be reviewed by experts. The false positives must be filtered out.  

This is a very expensive and very time-consuming process. However, over the past few years, malware average breakout times (the time required for the malware to propagate itself - i.e., to jump from device to device) has dropped from around ten hours down to around half an hour. This means that to contain any attack, it must be reliably detected and acted upon in well under half an hour.  

But the A.I.-based false-positive-plagued detection systems are generally incapable of reacting that rapidly. There is simply not sufficient time for the experts to review all of the alerts. Nor is there time to review the massive number of alerts that the new AI-generated malware is capable of precipitating. 

In cyberwarfare, delay is defeat. Treating AI as a magical cure does not eliminate risk. When defenders are told that a cybersecurity system is “intelligent” and that it will detect all the attacks it encounters, they are being sold a false sense of security. They are being sold security theater. They are being induced into a state of complacency that almost guarantees catastrophic failure. 

How to Fight the Newly Emerging Cyber War 

If we defenders are to prevail in the “next” war (in which we already engaged), we need to implement a few new strategies. These include: 

  • Implement Deterministic Malware Detection Systems 
  • Implement Detection Systems That Can Operate INSIDE OT Devices 
  • Use AI Systems Appropriately for Cyber-Defenses 
  • Engage the Power of Human Defenders 

Deterministic Malware Detection Systems 

As long as malware detection systems remain incapable of detecting the vast majority of new, previously undocumented, attacks, and as long these detection systems rely upon probabilistic algorithms that spew forth vast quantities of false positives, malware detection shall remain ineffective.  

ONLY deterministic systems capable of detecting both new, previously undocumented malware and previously seen malware at the time of injection (rather than at the time of execution) can provide a viable foundation for effective malware detection. 

Malware Detection Systems that Operate INSIDE of OT Devices 

Although there are many powerful cybersecurity tools that monitor network traffic and logfiles, the latest malware can now operate inside of an infected device with a level of sophistication. When it does so, it is able to produce reasonable looking network traffic and logfiles.  

Consequently, unless there is a monitoring system component that is also inside of a device, effective and comprehensive detection is impossible. Therefore, at least some components of a detection system must operate inside the devices being protected. 

Engage the Power of Human Defenders 

It has become fashionable to blame people for cybersecurity failures. Users click suspicious links, analysts miss alerts, and administrators misconfigure systems. But this framing is neither the entire picture nor is the situation necessarily as dire as it currently appears. 

The problem begins well before an incident ever occurs. For years, the cybersecurity industry has discouraged genuine understanding. The “mysteries” of how cyber defenses really work are cult-like, shared only with a small inner circle of technical elite.  

Complexity is promoted as an asset. The rationales for security procedures and the logic underpinning defense algorithms are hidden behind walls of jargon and technobabble. End user training is reduced to the rote learning of mindless, unquestioned procedures. True comprehension and understanding are not conveyed.  

In such environments, intelligent human judgment is replaced by enforced blind trust in opaque systems... and THAT is a serious problem. When people are treated as if they cannot be trusted to understand what is happening, they lose the capacity for situational awareness. They lose the motivation and the ability for true vigilance.  

By being untrusted, they naturally become untrustworthy. However, real security requires both situational awareness and vigilance. Without these two elements, there can be no true security. 

This industry-promoted loss of awareness is then compounded by the tools defenders are given to work with. Modern cybersecurity systems rarely present clear, timely alerts. Instead, they deliver delayed conclusions, probabilistic assessments, and overwhelming volumes of alerts.  

Critical signals are lost, forcing defenders to infer risk rather than clearly recognize threats. In these conditions, even skilled professionals are forced to operate reactively and without confidence. 

The human defenders are asked to respond to threats they cannot clearly see, using systems that do not detect with certainty. No amount of training can compensate for tools that obscure reality or deliver essential information too late for timely action. 

If awareness of the dangers and constant vigilance are the sine qua non of effective security, infantilization and induced complacency are its inimical enemies.  

Only by empowering the human defenders, by educating them with understanding (not by training them to blind obedience), and by providing them with the appropriate tools to do their jobs, can the fight for true cybersecurity be won! 

The Way Forward for Malware Detection 

There is a response to AI-generated malware that does not rely on speculative predictions, probabilistic pattern matching, and previously documented detections. It begins by discarding the erroneous assumption that all new malware must closely resemble old malware. 

Crytica’s RDAi malware detection algorithm is based upon a very basic premise: A computer is merely a machine that executes instructions. Those instructions are defined and authorized by those responsible for the system.  

In order for malware to operate, it must change a device’s instruction set. If it does not, it cannot change the behavior of the device. Therefore, any unauthorized change to a device’s instruction must be alerted upon. 

From this perspective, malware does not need to “look malicious” or resemble anything seen before. It is simply any unauthorized change to a device’s instruction set. 

Crytica’s Rapid Detection, Alert, and Isolation (RDAi™) system is built upon this principle. Rather than waiting for execution or suspicious behavior, RDAi monitors instruction integrity and detects unauthorized changes to those instruction sets; and it does so within seconds.  

We call this Instruction Set Integrity Monitoring (iNSiM™). The approach is binary and deterministic. Either a change has occurred, or it has not. Either the change is authorized, or it is not.  

Detection at injection alters the balance of power in modern cyberwarfare. Polymorphic malware loses its advantage because the external appearance of malware is irrelevant. Preemptive attacks lose their advantage because detection can now occur before defenses can be disabled. AI-generated malware loses its advantage because novelty is irrelevant. Massive “multi-warhead attacks” are deflected because of the speed and accuracy of deterministic detection. 

In a cyber war that is defined by speed and constant variation, RDAi replaces delayed recognition with immediate certainty. RDAi restores the defender’s ability to see real threats as soon as they arrive and before they can act. 

The Why of RDAi™  

Cyberwar is here and now. Nation states, criminal organizations, and hybrid actors are already deploying advanced malware against critical infrastructure, industrial systems, and supply chains.  

Operational technology and embedded devices were never designed to support traditional endpoint security tools. This makes them especially attractive targets for cyberattacks. 

Unfortunately, denial remains widespread. Many organizations believe they are protected because they have invested in “sophisticated” systems. However, in light of recent, highly publicized, successful attacks, this attitude should be changing.  

Nevertheless, we need to remain cautious. Security theater is alive and well, and very prevalent. It is a condition that is very harmful in peacetime. In wartime, it is fatal. It promotes complacency. It delays recognition of threats and prolongs exposure to advanced persistent threats. 

If we continue to rely upon the methods and the strategies of the past, the result is a foregone conclusion: Defeat.  

Crytica’s RDAi is a malware detection weapon suitable for the present and the future, built to work well with the weapons of the past. It was designed with the understanding that delayed detection is indistinguishable from failure.  

By detecting unauthorized instruction set changes, the Rapid Detection, Alert, and Isolation system provides the certainty required for modern cyberwarfare. To see this approach in action, reach out to our team.

Author
Smiling elderly man with glasses wearing a collared shirt.

C. Kerry Nemovicher, Ph.D.

CEO & President of Crytica Security
More about the author
AI Assistant
White circle with chat bubble icon.