Sophos researchers have uncovered a sophisticated malware-testing lab utilizing AI agents to develop and refine evasion techniques against major endpoint detection and response products like CrowdStrike and Microsoft Defender.
Key Points
- Threat actors used Claude Opus 4.5 agents to automate malware development, EDR testing, and infrastructure management within a virtualized Windows Server 2022 environment.
- The framework utilized the Model Context Protocol to connect AI assistants with Git repositories, enabling the testing of over 70 distinct evasion techniques.
- Attackers employed the Ludus platform for infrastructure deployment and the Cursor IDE to write Python-based payloads designed to bypass security software.
- The malicious toolkit included Cobalt Strike profiles, Telegram-based command-and-control mechanisms, and Cloudflare Workers to conceal backend operations.
- Sophos identified that the threat actors used "red-team" framing to bypass AI model safety guardrails, a tactic increasingly observed in global cyberattacks.