BREAKING
AI-Coded Malware Hits Active Directory
How the June 3 Intrusion Unfolded
1
RDP via stolen creds
↓
2
Stage in ProgramData
↓
3
Run Untitled1.ps1
↓
4
Exfil via s5cmd.exe
Script Mapped the Whole AD
Telltale Signs of Machine Authorship
Static vs Behavioral Detection
Static Detection
struggles
●
No reusable signature
●
AI varies syntax
Behavioral Detection
flagged it
●
Same system calls
●
Caught by SIEM
Detect Behavior, Not Code
AI NEWS BLITZ
Huntress documents one of the first cases of vibe-coded malware seen in the wild.