Attackers Use AI to Automate EDR Evasion Testing
Attackers are leveraging artificial intelligence to automate the process of testing and developing malware designed to evade endpoint detection and response (EDR) systems. Sophos researchers discovered a sophisticated red-team framework utilizing AI-generated Python scripts and a dedicated lab environment for iterative malware development and testing against multiple EDR solutions. This activity, linked to known ransomware operations, highlights the evolving tactics of threat actors seeking to bypass security measures.
A threat actor has been observed utilizing AI to create a highly automated EDR evasion lab. Sophos researchers identified a complex framework involving multiple Python scripts, partially AI-generated, that iteratively tested malware against EDR agents from Sophos, CrowdStrike, and Windows Defender. This lab utilized an Active Directory panel to orchestrate testing, analyze results, and refine malware for increased evasion capabilities. The attacker’s methodology mirrored a ‘build, test, analyze, refine’ cycle, incorporating vendor research and mapping techniques to MITRE ATT&CK frameworks.
