Skip to Content
View all events

AI-Based Malware Analysis for Cybersecurity

Published by Pearson

Intermediate to advanced content levelIntermediate to advanced

Unlock advanced AI-driven malware analysis with expert insights and practical tools

  • Learn how artificial intelligence transforms malware and cybersecurity.
  • Understand the tools and techniques necessary to detect and mitigate AI-powered malware attacks.
  • Engage in practical learning through live analysis and real-world examples of AI-enhanced malware such as BlackMamba and Revil Ransomware, combined with hands-on training in both static and dynamic malware analysis techniques.

Led by a leading academic expert in Cybersecurity and AI, Dr. Petar Radanliev, this engaging course provides theoretical and practical insights into the rapidly evolving threat landscape of AI-based malware. Participants will explore the intersection of AI and malware, learning how AI is used to create more sophisticated and evasive threats, as well as how cybersecurity professionals can counter these using AI-enhanced detection and mitigation tools.

Participants will be introduced to the core concepts of AI-based malware, along with an overview of static analysis techniques. They will also delve into advanced static analysis of AI-generated malware, focusing on tools such as Ghidra and DeepCode AI. In the second part, the focus shifts to dynamic analysis, providing hands-on experience using sandbox environments to observe malware behavior in real time. Participants will be challenged with real-world case studies focused on AI-driven threats and will explore advanced mitigation strategies.

By the end of the course, participants will be equipped with the knowledge and tools needed to address the growing challenge of AI-based malware.

What you’ll learn and how you can apply it

  • Analyze the evolving landscape of AI-powered malware and its implications for cybersecurity.
  • Apply the latest tools and strategies for detecting and analysing AI-driven malware, including hands-on experience with Ghidra, Cuckoo Sandbox, Vectra AI, and Falcon X AI.
  • Understand the techniques for applying static and dynamic analysis to real-world malware, enabling you to dissect and understand polymorphic viruses, AI-generated ransomware, and more.
  • Acquire and apply knowledge of using advanced malware analysis tools to identify and mitigate AI-powered threats.
  • Navigate the latest advancements in AI malware to stay ahead of rapidly evolving cybersecurity threats.

This live event is for you because...

  • This course is designed for experienced professionals and cybersecurity enthusiasts, particularly those in software development, data science, or information security. You'll learn to analyze and mitigate AI-powered malware with real-world tools and expert guidance.
  • Whether you are new to malware analysis or looking to deepen your understanding of AI-driven threats, this course provides the hands-on experience you need to be effective in today’s cybersecurity landscape.
  • Engaging with AI-powered malware without an in-depth understanding of its capabilities can leave your systems vulnerable. This course provides you with the latest insights and practical strategies to protect your organization from these sophisticated threats.

Prerequisites

  • Basic knowledge of malware analysis: Understanding of traditional malware detection methods will be helpful.
  • Familiarity with cybersecurity concepts: A foundational understanding of network security, endpoint protection, and malware behaviour is recommended.
  • Curiosity and willingness to learn: A strong interest in the rapidly growing field of AI-enhanced cybersecurity and the ability to think critically about its implications on global security.

Recommended Preparation

Recommended Follow-up

Schedule

The time frames are only estimates and may vary according to how the class is progressing.

Segment 1: Foundations of AI-Powered Malware (30 minutes)

  • Overview of AI in malware analysis: classification, anomaly detection, and automated feature extraction.
  • Recent examples of AI-powered malware: PromptLock ransomware (AI-assisted polymorphism), Lumma Stealer (infostealer with adaptive delivery), and UNC6032 fake AI sites (droppers and backdoors).
  • Exercise: Run a sample in Intezer Analyze and compare its AI-generated classification with a YARA-X auto-generated detection rule.

Q&A (5 minutes)

Break (5 minutes)

Segment 2: Understanding AI-Based Static Malware Analysis (30 minutes)

  • How AI enhances static analysis: byte embeddings, transformer-based classifiers, and explainability.
  • Limitations: adversarial obfuscation, polymorphism, and poisoned datasets.
  • Exercise: Use BinaryAI to upload a benign and a malicious file, then view the AI-generated classification alongside its interpretability dashboard.

Q&A (5 minutes)

Break (5 minutes)

Segment 3: Advanced Static Malware Analysis (20 minutes)

  • Analysing obfuscated or polymorphic malware using AI-assisted reverse engineering.
  • Explainable ML for static classifiers: why models predict malware and how to reduce false positives.
  • Exercise: Use DeepExplain-Sec to generate a saliency map of a malware sample and highlight the byte patterns that influenced the classification.

Q&A (5 minutes)

Break (5 minutes)

Segment 4: AI-Powered Malware Threats in 2024–2025 (20 minutes)

  • Case studies: PromptLock ransomware, FraudGPT/EvilGPT toolkits, and the UNC6032 campaign.
  • How attackers use AI for reconnaissance, phishing, and lateral movement.
  • Exercise: Run a dropper sample in ANY.RUN AI sandbox and generate an instant AI-assisted behavioural report.

Q&A (5 minutes)

Break (5 minutes)

Segment 5: Introduction to Dynamic Malware Analysis (20 minutes)

  • Behavioural analysis: tracing system calls, API sequences, and sandboxing outputs.
  • AI for detecting evasive behaviour.
  • Exercise: Use Malwarebytes to execute a malware sample and review the AI-generated summary of its first 30 seconds of activity.

Q&A (5 minutes)

Break (5 minutes)

Segment 6: Advanced Dynamic Analysis (20 minutes)

  • Detecting fileless and memory-only malware with AI-powered monitoring.
  • Process injection, sandbox evasion, and delayed execution tactics.
  • Exercise: Run AI in Memory Forensics on a captured memory image and quickly identify injected processes flagged by the AI model.

Q&A (5 minutes)

Segment 7: Real-World Case Studies (20 minutes)

  • Analysis of recent campaigns: PromptLock, Lumma Stealer, and AI-themed malware distribution.
  • Mapping threats to MITRE ATLAS and identifying detection gaps.
  • Exercise: Map PromptLock’s attack chain to MITRE ATLAS using Elastic AI-Hunt and identify one stage where AI detection improves coverage.

Q&A (5 minutes)

Segment 8: Wrap-Up & Defence Roadmap (15 minutes)

  • Multi-layered AI defences: integrating static, dynamic, and behavioural AI detection.
  • Governance and standards: NIST AI RMF v2.0, EU AI Act, and MITRE ATLAS.
  • Exercise: Generate a Sigma-AI detection rule for a known malware behaviour and load it into Elastic AI-Hunt for testing.

Q&A (5 minutes)

Your Instructor

  • Dr. Petar Radanliev

    Dr. Petar Radanliev lectures and supervises postgraduate master’s students’ research dissertations on AI and cybersecurity at the Department of Computer Science, University of Oxford. He is also a Lecturer/Instructor at Pearson and O’Reilly (USA), while conducting research on digital identity system security at the Alan Turing Institute, based at the British Library in London. After completing his PhD in 2013/14, Petar held postdoctoral research appointments at Imperial College London, the University of Cambridge, the Massachusetts Institute of Technology, and the Department of Engineering Science at the University of Oxford, where he remained for seven years before moving to his current position. His work spans artificial intelligence, cybersecurity, post-quantum security, and blockchain security. This research has led to an H-index of 25 (as indexed by Web of Science and Scopus), over 3,700 citations, more than 100 peer-reviewed publications, and four authored books. In recognition of his contributions, Petar has received major funding awards, including a Fulbright Fellowship and the Prince of Wales Innovation Award.

Skill covered

Malware