Attacker Used AI to Build Custom PowerShell Recon Malware
Huntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Windows Server that the attacker had used to map out the victim’s Active Directory environment. […]

During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Windows Server that the attacker had used to map out the victim’s Active Directory environment. The script hadn’t been downloaded from a public repository or pulled from a known offensive toolkit. It was custom-built, almost certainly by prompting an AI model until the output worked. Huntress researchers reconstructed the full script from PowerShell script block logging, specifically Event ID 4104 in the Microsoft-Windows-PowerShell/Operational log.
“The script, enthusiastically titled “100% Working AD Information Gathering Script – FULLY FIXED”, is a highly aggressive, noisy, custom-built AD enumeration tool. It doesn’t try to hide its functions, and has a number of distinct and interesting phases.” reads the report published by Huntress.
Related breach coverage
- Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances2026-07-20
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks […]
- Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network2026-07-18
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. Daxin is a Windows kernel-mode rootkit that Symantec first documented […]
- CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers2026-07-20
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests. “heap […]
- Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign2026-07-16
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of […]
