AI-built ransomware toolkit automates EDR evasion, AD discovery
ID: 1917e74e-68d4-57ac-bd95-f2f9c5369b56
STIX ID: report--1917e74e-68d4-57ac-bd95-f2f9c5369b56
Feed Name: Bleeping Computer
Researchers at Sophos discovered an AI-assisted ransomware development framework that automates Active Directory discovery and iteratively generates EDR-evasive payloads (primarily Rust/Go) using multiple AI agents (Cursor, Claude Opus). The toolkit included Cobalt Strike profiles, Telegram-based C2, Python scripts for shellcode injection, and a Cloudflare Worker redirector; modules were tested against Sophos, CrowdStrike, and Windows Defender, and evidence (Cobalt Strike logs and ransom-related artifacts) indicated criminal ransomware use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
