Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

AI accelerates development of ransomware toolkit with EDR evasion capabilities

A threat actor is leveraging an AI-assisted ransomware toolkit that automates Active Directory discovery and employs multiple techniques to evade EDR solutions, including disguising Cobalt Strike traffic, using a Telegram bot for C2, and injecting shellcode into legitimate Windows processes. The toolkit was tested against Sophos, CrowdStrike, and Microsoft EDR products, with AI agents significantly accelerating its development by researching bypass techniques and iteratively testing payloads. While the malware itself does not contain embedded AI, this use of AI dramatically shortens the time between public security research and its weaponization by adversaries.
Read Full Article →

Ransomware AI accelerates development of ransomware toolkit with EDR evasion capabilities June 3, 2026 Share By SC Staff A threat actor is leveraging an AI-powered ransomware attack toolkit that automates Active Directory discovery and aids in evading endpoint detection and response (EDR) solutions. The development and refinement of this toolkit, including its initial coding, analysis, and revisioning, were significantly assisted by AI agents like Cursor and Claude Opus, with some agents specifically tasked with researching security posts for various bypass techniques. This advanced toolkit was tested against EDR solutions from Sophos, CrowdStrike, and Microsoft, as reported by Bleeping Computer. The toolkit, discovered by Sophos, includes features such as Cobalt Strike profiles to disguise beacon traffic, a Telegram bot API for command and control, Python scripts for injecting shellcode into legitimate Windows executables, and a Cloudflare Worker to obscure the C2 server. Researchers confirmed its use in cybercriminal ransomware operations, noting that while AI assisted in its development, the overall workflow remains human-driven. The AI agents were instrumental in documenting bypass techniques, mapping them to the MITRE ATT&CK framework, and iteratively testing payloads against EDR solutions. This modular payload generator wraps payloads in encryption and evasion techniques to resist detection. While AI was not found embedded in deployed malware, its use significantly shortens the time between the release of offensive security research and its implementation by threat actors, posing a growing challenge for cybersecurity defenses. Source: Bleeping Computer An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Malware WeedHack malware campaign targets over 116,000 Minecraft players SC Staff June 3, 2026 The WeedHack malware is distributed through malicious Minecraft-related mods, clients, and utilities promoted via YouTube and search engine poisoning. Malware DriveSurge actor uses ClickFix and FakeUpdates to distribute malware via compromised websites SC Staff June 2, 2026 The DriveSurge threat actor operates as an initial access broker, utilizing a pay-per-install model to facilitate subsequent attacks, according to research by SilentPush. Malware Malware hides in Steam comments to infect WordPress sites SC Staff June 1, 2026 The malware campaign, discovered in July 2025, has affected approximately 1,980 WordPress sites. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article