Skip to content
Preprint

Tiny Enough to Break In: Agentic Remote Access Trojans Powered by Small Language Models

Aug 2026 · 1 citation · 33 references
Computer Science

TL;DR

This work examines cyber threats that reason, act, and adapt locally without continuous human direction through an Agentic Remote Access Trojan augmented with a locally deployed Small Language Model (SLM), and tests whether a model this small can support autonomous cyber decision-making.

Abstract

Agentic artificial intelligence raises a new security concern: cyber threats that reason, act, and adapt locally without continuous human direction. We examine this threat through an Agentic Remote Access Trojan (agentic RAT): a Remote Access Trojan augmented with a locally deployed Small Language Model (SLM). The SLM interprets host and network observations, selects actions, recovers from failed steps, and reduces reliance on an external operator. We implement the concept in a controlled, network-isolated lab built from Kali Linux, a Metasploitable2 target, LM Studio, and a local 8-billion-parameter Dolphin-family model. We then test whether a model this small can support autonomous cyber decision-making. This is architecturally feasible today. On commodity hardware, with no cloud service and no operator in the loop, the SLM closed the full observe-decide-act cycle: it interpreted ranked reconnaissance evidence supplied by the controller, selected actions, and obtained verified root-shell access on real vulnerable services. However, it is not yet operationally reliable. The same model hallucinated commands, misread output, and recovered from failure inconsistently, completing 10.9% of a deliberately strict checklist. That gap reflects the limits of today's small models, not a ceiling on the concept. As SLMs improve, agentic endpoint systems may become more practical, more autonomous, and harder to detect, straining existing monitoring, containment, and policy-enforcement mechanisms. Real-world incidents in 2025-2026 already show AI-driven intrusions moving from concept toward practice. That makes the local, self-contained variant we study a plausible near-term direction, not a hypothetical one.

View source

Similar papers

Preprint Aug 2026

SynChain: Inducing Computer-Use Agent Systems to Construct Their Own Attack Chains

This work introduces SynChain, a self-synthesized attack paradigm utilizing persistence-aware directed supervised fine-tuning to induce agents to create poisoned yet benign-looking artifacts, proving that securing CUAs requires provenance-aware reasoning over cross-task execution trajectories.

Fuyao Zhang, Jiaming Zhang, Che Wang et al. · 0 citations
Review Aug 2026

ClawSentry: A Progressive Multi-Tier Security Monitor for Safeguarding Autonomous LLM Agents

This work argues that agentic risk is progressive: it can enter at four loci of the agent control loop--skill admission, invocation-time intent, execution-time effect, and post-action consequence--while a denied dangerous objective can reappear across surface forms, tools, or turns.

Kai Wang, Zeming Wei, Biaojie Zeng et al. · 0 citations
#artificial intelligence Preprint Sep 2026

SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations Center

Large language model (LLM) agents are increasingly proposed as autonomous SOC analysts, but two limitations make them unreliable at enterprise scale: a finite context window cannot hold a multi-thousand-host authentication graph, and free-form generation offers no guarantee that a recommended containment action is cons...

Uday Vallabhaneni, Cassie L. Cagwin, David J. Wild · 1 citation
Preprint Aug 2026

NiyamAI - An Intent-Bound AI Agent with Cryptographically Verifiable Guardrails using Zero-Knowledge Proofs

NiyamAI is presented, an intent bound runtime guardrail architecture providing cryptographically verifiable execution integrity for autonomous agents and subjects its own enforcement mechanism to 18 adversarial vectors across six classes, disclosing two implementation vulnerabilities identified and remediated during de...

Aditya Katkar, Om Karkele, Kartik Mandhane et al. · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.