AI Shortens the EDR Bypass Loop

The shift is not that malware now has AI in it. The shift is that AI is being used to speed up the build-test-refine cycle for EDR evasion, so defenders face faster turnover in bypasses instead of one-off clever samples. The human still sets the goal; the agents just make iteration much faster. Sophos found that workflow in a malware-testing lab tied to AI coding tools, with scripts and a Git repository used to generate, test, and revise evasions against Sophos, CrowdStrike, and Microsoft EDR. The lab also included a control machine, command-and-control setup, and techniques drawn from public research, and Sophos linked the activity to ransomware and data theft operations without naming the actor. The practical risk is speed. Once attackers can turn detection ideas into working evasions faster, the gap between public defense research and deployed bypasses gets shorter, and the same workflow can be reused across commercial endpoint products.

Part of the PlainSec briefing for 2026-06-04

Sources