Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns: SolarWinds Serv-U Vulner Vulnerability Exploited
June 6, 2026
Critical RCE in Hugging Face Transformers Allows Attacks
June 6, 2026
Discover the Top 5 Best Simulated DDoS Attack Tools
June 6, 2026
Home/CyberSecurity News/AI Tools Automate Active Directory Attacks & EDR Evasion
CyberSecurity News

AI Tools Automate Active Directory Attacks & EDR Evasion

A threat actor recently leveraged AI-assisted tools to automate Active Directory discovery. These tools also facilitated testing of endpoint detection and response (EDR) evasion techniques, signaling...

Emy Elsamnoudy
Emy Elsamnoudy
June 3, 2026 3 Min Read
15 0

A threat actor recently leveraged AI-assisted tools to automate Active Directory discovery. These tools also facilitated testing of endpoint detection and response (EDR) evasion techniques, signaling the rise of AI-supported post-exploitation frameworks.

The activity was identified after a suspicious endpoint triggered alerts tied to payloads stored in a user directory.

Investigation revealed a collection of malicious components forming a structured attack toolkit. These included customized Cobalt Strike profiles designed to mimic legitimate web traffic.

Telegram bot–based command-and-control channel to hide communications within trusted infrastructure.

Python scripts capable of injecting shellcode into legitimate Windows executables while maintaining normal functionality. A Cloudflare Worker was also used as a redirector to obscure the true backend C2 server.

Hackers Use AI Red Team Tools

A key finding was the presence of partially AI-generated Python scripts, many written in Russian, alongside a Git repository that contained a broader automation framework.

This framework combined an automated AD discovery panel with a controlled lab environment used to iteratively develop and test malware against leading EDR platforms such as Sophos, CrowdStrike, and Microsoft Defender.

The AD discovery system did not operate as a fully autonomous large language model. Instead, it followed a structured decision tree model, collecting results from executed tasks, selecting predefined next steps, and dispatching actions to remote agents.

Diagram showing AI’s role in the malware development workflow (source : sophos)
Diagram showing AI’s role in the malware development workflow (source : sophos)

This allowed semi-automated reconnaissance across enterprise environments while maintaining predictable execution paths. The threat actor built the testing environment using virtual machines provisioned through Ludus.

Multiple Windows Server 2022 systems were configured to evaluate bypass techniques against different EDR agents, alongside a separate Ubuntu system hosting a Sliver command-and-control server.

Development was supported by an AI-native IDE, Cursor, and coordinated through multiple AI agents with assigned roles.

One primary AI agent, powered by Claude Opus, managed orchestration and rule-setting. In contrast, others handled testing, operational security improvements, documentation, and infrastructure deployment.

Article ingestion and technique mapping instructions for AI agents (source : sophos)

Communication between agents and the code repository was managed using the Model Context Protocol, enabling automated commits and iterative development cycles.

The framework also incorporated research on external threats. AI agents were instructed to ingest publicly available security blogs, extract attack techniques, map them to MITRE ATT&CK, and reproduce them within the lab.

Sources included well-known security firms and red team research providers. This process enabled rapid prototyping of attack techniques based on real-world methodologies.

At the core of the framework was a modular payload generator written in Python that produced executables in Rust and Go.

These payloads were wrapped in layers of encryption and evasion logic, allowing attackers to test over 70 different techniques.

While initial success rates were low, repeated iterations reportedly improved bypass effectiveness, though results remain partially unverified.

Sophos researchers assess that this framework, while presented as red team tooling, is likely intended for real-world intrusions, including ransomware deployment and data theft.

The use of AI significantly accelerates development cycles but does not fundamentally change defensive requirements.

Organizations are advised to maintain strong security baselines, including timely patching, multi-factor authentication, and comprehensive EDR deployment, as attackers increasingly use AI to identify and exploit defensive gaps.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Ivanti ITSM Flaw Grants Attackers Admin Privilege Vulnerability Lets

Next Post

OpenClaw 0-Day Flaws Hijack Trusted Five Attackers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Malicious Python Package Mimics Legitimate Parsimon
June 5, 2026
Hackers Weaponize Trusted Tools to Deploy Not Increasingly Weaponizing
June 5, 2026
Magecart Attack Uses Stripe as Malware Command Server
June 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us