logo

AI-built ransomware toolkit automates EDR evasion, AD discovery

ID: 1917e74e-68d4-57ac-bd95-f2f9c5369b56

STIX ID: report--1917e74e-68d4-57ac-bd95-f2f9c5369b56

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: Bill Toulas

...
...

Researchers at Sophos discovered an AI-assisted ransomware development framework that automates Active Directory discovery and iteratively generates EDR-evasive payloads (primarily Rust/Go) using multiple AI agents (Cursor, Claude Opus). The toolkit included Cobalt Strike profiles, Telegram-based C2, Python scripts for shellcode injection, and a Cloudflare Worker redirector; modules were tested against Sophos, CrowdStrike, and Windows Defender, and evidence (Cobalt Strike logs and ransom-related artifacts) indicated criminal ransomware use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.