news.mlab.sh
Back to the feed
ransomware

AI-built ransomware toolkit automates EDR evasion, AD discovery

High
Summary

A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cursor and Claude Opus, generates sophisticated payloads and utilizes techniques like mimicking web requests and leveraging Telegram for command and control. This highlights the increasing use of AI in cybercrime and the challenge of defending against rapidly evolving attack methodologies.

The Sophos team discovered this AI-driven ransomware toolkit in action when it triggered alerts on a customer’s system. The toolkit’s core functionality involves automating the discovery of Active Directory (AD) environments, a critical step in ransomware campaigns. It achieves this through a complex framework incorporating Cobalt Strike profiles to mask beacon traffic, a Telegram-based C2 channel, and Python scripts for injecting shellcode into legitimate Windows executables. The use of a Cloudflare Worker adds another layer of obfuscation, redirecting traffic to the actual C2 server. This demonstrates a sophisticated approach to bypassing traditional security controls.

Read the full article at BleepingComputer