logo

Malicious PowerShell script pushing malware looks AI-written

ID: d55f506e-7867-5f94-a6b6-8a051843326b

STIX ID: report--d55f506e-7867-5f94-a6b6-8a051843326b

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-04-10

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Proofpoint researchers observed TA547 using a PowerShell-based, likely LLM-assisted loader in a March phishing campaign impersonating Metro Cash & Carry to deliver the Rhadamanthys infostealer to dozens of German organizations; attackers distributed password-protected ZIPs containing .LNK shortcuts that launched a PowerShell script which decoded and executed Rhadamanthys entirely in memory, and the script's unusually extensive, well-formed comments and variable names led investigators to suspect generative AI was used to craft the code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.