← Back to news

AI-built ransomware toolkit automates EDR evasion, AD discovery

BleepingComputer02/06/2026, 20:01
Read full article →

Summary

AI-Generated

Key Points:

  • A new AI-built ransomware toolkit is being used by threat actors to automate Active Directory discovery and evade EDR solutions.
  • The toolkit has been tested against EDR products from Sophos, CrowdStrike, and Microsoft, with indications of successful evasion techniques in a customer environment.
  • Organizations should enhance their EDR configurations and conduct thorough assessments to detect potential misuse of automated tools.

Technical Details: The toolkit utilizes Python scripts to generate payloads primarily in Rust and Go, employing various evasion techniques. The development process is human-driven, with AI assisting in coding and testing against over 70 techniques.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1016 - System Network Configuration Discovery (Discovery)
  • T1046 - Network Service Scanning (Discovery)
  • T1203 - Exploit Public-Facing Application (Initial Access)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.