A January 8, 2025 threat forecast from Goldilock, a NATO-backed UK cyber firm, predicting that within two years AI-enhanced malware capable of a Stuxnet-class event will emerge. The forecast describes the distinction between conventional and AI-powered malware, cites early examples, and outlines recommended defenses.
Central forecast
Goldilock forecasts that within two years a Stuxnet-class event will occur, enhanced with AI capabilities. The malware it describes would autonomously identify targets, compromise them, and continuously modify its tactics to evade detection. The forecast frames 2025 as a period of early AI-malware emergence, with primary targets being critical infrastructure, data centers, and sensitive networks. Follow-up coverage by Axios placed agentic malware at around 2027.
The forecast distinguishes AI-powered malware from conventional malware along three dimensions:
| Conventional | AI-Powered |
|---|---|
| Predefined instructions | Autonomous learning/adaptation |
| Static attack patterns | Continuously evolving tactics |
| Signature-detectable | Increasingly difficult to detect |
Early evidence cited
Goldilock points to two existing tools as early indications. It states that BlackMatter ransomware uses AI to refine encryption strategies and analyze targets in real time, and that Cobalt Strike adaptations demonstrate AI-powered tactics circumventing EDR tools.
Recommended defenses
The forecast recommends government and industry investment in AI-driven cybersecurity innovations, adaptive and anticipatory defense mechanisms, and cross-sector information sharing.
Provenance and reception
Goldilock describes the forecast as the most specific threat forecast for AI-powered malware, giving a two-year horizon for a Stuxnet-class event, and notes its NATO backing as institutional weight. The forecast pairs with a separate one-year AI-agent attack prediction (Source: Raw Sources/Mandia - AI Agent Cyberattacks Warning 2025.md); read together, the two point to approximately 2026 for a first high-profile AI-attributable attack.
Relationships
- supports: Planned AI and Cybersecurity, Managing Advanced Cyber Risks in Frontier AI Frameworks, CBRN Uplift (parallel risk-class).
- related: (Source: Raw Sources/Mandia - AI Agent Cyberattacks Warning 2025.md), (Source: nytimes.com), (Source: washingtonpost.com), Project Glasswing: Securing Critical Software for the AI Era, GPT-5.3-Codex System Card, GPT-5.4 Thinking System Card.
- depends-on: Goldilock (company page planned).