AI · 118 giorni fa
Il cambiamento non è che il malware ora abbia AI al suo interno. Il cambiamento è che AI viene usata per velocizzare il ciclo build-test-refine per l'EDR evasion, così i defender si trovano ad affrontare un turnover più rapido nei bypass invece che sample ingegnosi one-off. L'umano definisce ancora l'obiettivo; gli agenti rendono semplicemente l'iterazione molto più veloce.
4 fonti che coprono questa storia
Attackers Use AI to Automate EDR Evasion Testing
Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
AI-built ransomware toolkit automates EDR evasion, AD discovery
A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions.
Threat Actor Uses AI to Build EDR Evasion Tools
A threat actor used AI coding tools to build and test EDR evasion malware, Sophos finds
Sophos uncovers AI-powered malware lab built for EDR evasion - Help Net Security
A threat actor used AI agents, Claude, and a malware-testing lab to develop and refine EDR evasion techniques, according to Sophos.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-04