AUTO-UPDATED

Sophos uncovers AI-powered malware lab built for EDR evasion

Sophos researchers have uncovered a sophisticated malware-testing lab utilizing AI agents to develop and refine evasion techniques against major endpoint detection and response products like CrowdStrike and Microsoft Defender.

Key Points

  • Threat actors used Claude Opus 4.5 agents to automate malware development, EDR testing, and infrastructure management within a virtualized Windows Server 2022 environment.
  • The framework utilized the Model Context Protocol to connect AI assistants with Git repositories, enabling the testing of over 70 distinct evasion techniques.
  • Attackers employed the Ludus platform for infrastructure deployment and the Cursor IDE to write Python-based payloads designed to bypass security software.
  • The malicious toolkit included Cobalt Strike profiles, Telegram-based command-and-control mechanisms, and Cloudflare Workers to conceal backend operations.
  • Sophos identified that the threat actors used "red-team" framing to bypass AI model safety guardrails, a tactic increasingly observed in global cyberattacks.

Why it Matters

This discovery highlights how threat actors are leveraging AI-native development tools to accelerate the creation of evasive malware and automate the testing of security bypasses. While the effectiveness of these AI-generated tools may be limited by model hallucinations, the integration of automated agents into the cyberattack lifecycle poses a significant challenge for traditional endpoint defense strategies.
Help Net Security Published by Sinisa Markovic
Read original