31185686692?profile=RESIZE_400xAnalysts at Sophos' X-Ops group have identified a threat actor operating within a customer environment after an anomalous endpoint generated alerts.  The device, located in a tenant, contained multiple malicious files stored in the directory C:\Users\User\Documents\test. These included Cobalt Strike profiles crafted to mimic legitimate web traffic, a Telegram bot application programming interface mechanism for external command and control communication, Python scripts designed to inject shellcode into legitimate Windows executables while maintaining original functionality, and a Cloudflare Worker configured as a redirector to conceal the true backend command and control server.  Further examination uncovered a Git repository housing a comprehensive framework.  This included an automated Active Directory discovery panel and a dedicated laboratory for iterative malware development and testing.[1]

The panel collected results from completed tasks, selected subsequent actions from a predefined list, assigned work to remote agents, and reassessed outcomes upon return.  Although the process incorporated artificial intelligence elements, it did not rely on an autonomously reasoning large language model.

Several Python scripts, some written in Russian, showed partial artificial intelligence generation.  The threat actor employed a virtual machine system provisioned through Ludus and the artificial intelligence-native integrated development environment Cursor to build tools targeting endpoint detection and response agents.  Multiple virtual machines ran Windows Server 2022: one for Sophos, one for CrowdStrike, one without any endpoint detection and response agent as a control, and an Ubuntu-based Sliver command and control server.

The actor configured several artificial intelligence agents with distinct roles. One agent, powered by Claude Opus 4.5, managed core operations and established rules for the others.  Additional agents handled testing against endpoint detection and response solutions, operational security hardening, documentation, proxy stress testing, and virtual machine deployment.  Code commits and issues were relayed to Git through the Model Context Protocol.

The framework drew techniques from public research published by Kaspersky, Palo Alto Networks, Bishop Fox, and SpecterOps.  A central Python-based payload generator produced modular Windows loaders, primarily in Rust and Go.  These incorporated layers of encryption, evasion, and alternative execution methods. Nearly 80 modules evaluated over 70 distinct techniques.  Initial tests recorded high failure rates, but subsequent iterations reportedly achieved near-universal success against the monitored endpoint detection and response agents, although the full documentation did not fully corroborate this outcome.  While presented as a red team framework, the setup appears designed to support stealthy post-exploitation activity. Sophos Counter Threat Unit researchers have connected the development to prior ransomware deployment and data theft campaigns.

The adoption of artificial intelligence agents speeds up tool creation and testing of evasion methods, reducing barriers for complex attacks.  Organizations should nevertheless maintain established defense-in-depth measures.  Critical practices include timely patching, multi-factor authentication, modern authentication such as passkeys, and comprehensive deployment of effective endpoint detection and response solutions.

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

[1] https://www.cybersecurityintelligence.com/blog/threat-actor-employs-ai-for-edr-evasion-development-9446.html

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!