Threat Actor Developed EDR Evasion Malware Using AI Coding Tools (infosecurity-magazine.com)
- AI-assisted malware development using Cursor and Claude Opus for EDR evasion
- Nearly 80 modules covering over 70 techniques, tested against Sophos, CrowdStrike, Microsoft EDR
- Sophos assesses red team cover story as likely false, links to ransomware and data theft
"Sophos X-Ops discovered a threat actor using AI coding tools, including Cursor and Claude Opus, to develop malware that bypasses endpoint detection and response (EDR) software. The actor built a lab with Python scripts—partially AI-generated and written in Russian—producing nearly 80 modules covering over 70 techniques. While framed as a red team project, Sophos assesses the label as likely a cover for actual post-exploitation activity, linked to ransomware and data theft operations. The AI was not autonomous; human review remained critical. Sophos recommends defense-in-depth fundamentals."
no comments yet.