Attacker Used AI to Build Custom PowerShell Recon Malware
Huntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Windows Server that the attacker had used to map out the victim’s Active Directory environment. […]

During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Windows Server that the attacker had used to map out the victim’s Active Directory environment. The script hadn’t been downloaded from a public repository or pulled from a known offensive toolkit. It was custom-built, almost certainly by prompting an AI model until the output worked. Huntress researchers reconstructed the full script from PowerShell script block logging, specifically Event ID 4104 in the Microsoft-Windows-PowerShell/Operational log.
“The script, enthusiastically titled “100% Working AD Information Gathering Script – FULLY FIXED”, is a highly aggressive, noisy, custom-built AD enumeration tool. It doesn’t try to hide its functions, and has a number of distinct and interesting phases.” reads the report published by Huntress.
Related breach coverage
- Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances2026-07-20
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks […]
- Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network2026-07-18
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. Daxin is a Windows kernel-mode rootkit that Symantec first documented […]
- Why brand impersonation is becoming an initial access vector2026-07-30
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing […]
- MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection2026-07-27
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek.