Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active Directory (AD). The script, titled ‘100% Working AD Information Gathering Script – FULLY FIXED,’ exhibited telltale signs of AI assistance, including prompt iteration titles, placeholder strings, and over-engineered code with a five-step cascading fallback mechanism to locate Domain Controllers. The attack chain began with RDP access using pre-compromised credentials, followed by staging tools in the ‘C:ProgramData’ folder. The script systematically harvested AD users, computers, groups, OUs, and trusts, storing data in a staging directory. Approximately 30 minutes later, the attacker deployed s5cmd and SharpShares to enumerate network shares. Data was exfiltrated to a remote server, with an HTML report summarizing the theft. Huntress noted that the script’s ‘noisy’ and ‘highly aggressive’ nature reflects a hybrid approach prioritizing speed over stealth, lowering the barrier to entry for less-skilled actors.
In a related report, Sygnia described an AI-assisted cloud attack against an AWS-based environment that progressed from initial access to broad compromise within 72 hours. The attacker used familiar cloud techniques, chaining weaknesses across application services, AWS resources, CI/CD workflows, and data stores. The attack involved repeated credential discovery, secrets harvesting, persistence attempts, and data exfiltration, with artifacts masked as pentesting. Sygnia emphasized that AI did not introduce new techniques but reduced the time and effort to operationalize existing adversary behaviors at scale.
Companies: Huntress, Sygnia, Amazon Web Services
Products: s5cmd, SharpShares, PowerShell
Original source: thehackernews.com