logo

Attackers Use AI to Automate EDR Evasion Testing

ID: dd7d39d0-ab99-5080-9f3d-7793f8d1b622

STIX ID: report--dd7d39d0-ab99-5080-9f3d-7793f8d1b622

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-06-03

Date Updated: 2026-06-15

Author: Alexander Culafi

...
...

Sophos X-Ops detected an attacker using AI-assisted development and an automated EDR-evasion lab: multiple Python scripts (some AI-generated), an Active Directory orchestration panel, and virtual machines configured to test malware against Sophos, CrowdStrike, and Windows Defender. The actor used LLM-powered tools to coordinate and automate testing and operational security, iteratively refining payloads to bypass EDRs; Sophos links the activity to ransomware deployment and data-theft operations and recommends standard mitigations such as patching, MFA, and broad EDR deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.