AI-built ransomware automates EDR evasion, AD discovery

TL;DR. A threat actor uses an AI-built ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response solutions, as reported by Sophos. - AI agents Cursor and Claude Opus assisted in developing the malware by generating code and checking security research. - The toolkit includes Cobalt Strike profiles, a Telegram bot C2, and Python scripts for shellcode injection. - Sophos observed the framework testing EDR tools from Sophos, CrowdStrike, and Microsoft. - Researchers confirmed the toolkit's use in criminal activity, not legitimate red team operations.

Sources

Back to QLANKR News