Sophos says it detects an AI-assisted malware development and testing setup used to refine endpoint detection and response (EDR) evasion techniques. The investigation starts after an anomalous endpoint in a customer environment triggers alerts connected to malicious payloads located in a “testing” directory, which suggests the activity is part of an ongoing development effort rather than a one-off intrusion. Sophos reports the files and artifacts point to a broader framework aimed at evading defensive detection. The company also describes an environment containing elements consistent with threat emulation and command-and-control disguise, including Cobalt Strike profiles configured to make beacon traffic resemble legitimate web requests. Sophos further links the setup to messaging infrastructure used for remote communications, including Telegram-based components referenced in the analysis. According to Sophos, the threat actor uses AI coding tools to build and test evasion-related malware, enabling faster iteration of techniques designed to bypass EDR controls. Across the reporting, the key theme is the use of AI to support the creation and evaluation of endpoint evasion tooling within a dedicated malware-testing framework.
Sophos reports AI-assisted malware lab for EDR evasion development
Sophos says it detects an AI-assisted malware development and testing setup used to refine endpoint detection and response (EDR) evasion techniques. The investigation starts after an anomalous endpoin...
- Sophos investigates an anomalous endpoint that triggers alerts tied to malicious payloads in a testing directory.
- Sophos says a threat actor uses AI coding tools to build and test EDR-evasion malware.
- The activity includes a broader framework aimed at developing and refining techniques to evade endpoint defenses.
- Sophos reports Cobalt Strike profiles configured to make beacon traffic appear like legitimate web requests.
- The setup includes messaging and remote communication components, including Telegram-based elements.
A threat actor used AI coding tools to build and test EDR evasion malware, Sophos finds
2 months agoA threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques, according to Sophos. The investigation began after an anomalous endpoint in a customer environment triggered alerts tied to malicious payloads originating from a testing directory. The files pointed to a broader framework focused on evading detection. The environment contained Cobalt Strike profiles designed to disguise beacon traffic as legitimate web requests, a Telegram-based … More → The post Sophos uncovers AI-powered malware lab built for EDR evasion appeared first on Help Net Security.
2 months ago
Visa expands cybersecurity support for clients as AI-era threats evolve
Visa is expanding support for its clients and the payments industry to help organizations manage cybersecurity challenge...
NBEMS schedules additional FMGE on Oct 31; January 2027 exam rescheduled
The National Board of Examinations in Medical Sciences (NBEMS) announces changes to the Foreign Medical Graduate Examina...
AI coding tools reshape software work, shifting focus to review, governance, and higher-level judgment
Software development is increasingly using AI tools to write or draft code faster, but multiple accounts describe why pr...