AI · 103 days ago
The shift is not that malware now has AI in it. The shift is that AI is being used to speed up the build-test-refine cycle for EDR evasion, so defenders face faster turnover in bypasses instead of one-off clever samples. The human still sets the goal; the agents just make iteration much faster.
Sophos found that workflow in a malware-testing lab tied to AI coding tools, with scripts and a Git repository used to generate, test, and revise evasions against Sophos, CrowdStrike, and Microsoft EDR. The lab also included a control machine, command-and-control setup, and techniques drawn from public research, and Sophos linked the activity to ransomware and data theft operations without naming the actor.
The practical risk is speed. Once attackers can turn detection ideas into working evasions faster, the gap between public defense research and deployed bypasses gets shorter, and the same workflow can be reused across commercial endpoint products.
4 sources covering this story
Attackers Use AI to Automate EDR Evasion Testing
Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
AI-built ransomware toolkit automates EDR evasion, AD discovery
A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions.
Threat Actor Uses AI to Build EDR Evasion Tools
A threat actor used AI coding tools to build and test EDR evasion malware, Sophos finds
Sophos uncovers AI-powered malware lab built for EDR evasion - Help Net Security
A threat actor used AI agents, Claude, and a malware-testing lab to develop and refine EDR evasion techniques, according to Sophos.
Part of the PlainSec briefing for 2026-06-04