logo

Pointing a Cursor at evading detection

ID: 0f51ed5a-dabb-57eb-a0d8-77ff10a77808

STIX ID: report--0f51ed5a-dabb-57eb-a0d8-77ff10a77808

Feed Name: Sophos Blogs

Threat Score
78/100

Date Published: 2026-06-02

Date Updated: 2026-06-05

...
...

**Executive Summary:** Sophos X-Ops uncovered a threat actor using AI-assisted development and orchestration to build a red‑team style post‑exploitation testing framework that produced modular loaders, Cobalt Strike profiles, Telegram-based C2, and other tooling designed to evade EDRs; the framework was used to iterate techniques against Sophos, CrowdStrike, and Windows Defender and is linked to ransomware and data theft operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.