Particle.news
Download on the App Store

Sophos Exposes AI‑Assisted Lab That Built EDR‑Evasion Tooling

The report shows attackers used multiple AI agents to speed a human‑supervised build-test-refine cycle that could make stealthy post‑compromise tools easier to produce.

Overview

  • Sophos researchers discovered the activity on Tuesday, June 2, 2026, after an endpoint in a customer environment flagged malicious test files that led to a Git repository and a virtualized testing lab.
  • Multiple AI agents operated inside an AI-native IDE called Cursor with a Claude Opus 4.5 agent coordinating tasks and the Model Context Protocol linking agents to code and data.
  • At the lab’s core was a Python payload generator that produced custom loaders and nearly 80 modules used to exercise more than 70 EDR evasion techniques against products from Sophos, CrowdStrike, and Microsoft Defender.
  • Sophos found discrepancies between the lab’s internal claims of near-universal success and the test output it could review, and it linked the tooling to ransomware and data‑theft activity without naming a specific group.
  • Researchers advised defenders to stick to defense-in-depth measures such as timely patching, multi-factor authentication or passkeys, wide EDR coverage, and to monitor for attempts to bypass model safeguards because AI shortens the time from published research to usable attack code.