Sophos says it detects an AI-assisted malware development and testing setup used to refine endpoint detection and response (EDR) evasion techniques. The investigation starts after an anomalous endpoint in a customer environment triggers alerts connected to malicious payloads located in a “testing” directory, which suggests the activity is part of an ongoing development effort rather than a one-off intrusion. Sophos reports the files and artifacts point to a broader framework aimed at evading defensive detection. The company also describes an environment containing elements consistent with threat emulation and command-and-control disguise, including Cobalt Strike profiles configured to make beacon traffic resemble legitimate web requests. Sophos further links the setup to messaging infrastructure used for remote communications, including Telegram-based components referenced in the analysis. According to Sophos, the threat actor uses AI coding tools to build and test evasion-related malware, enabling faster iteration of techniques designed to bypass EDR controls. Across the reporting, the key theme is the use of AI to support the creation and evaluation of endpoint evasion tooling within a dedicated malware-testing framework.