{"id":1737,"date":"2026-07-13T17:43:50","date_gmt":"2026-07-13T17:43:50","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1737"},"modified":"2026-07-13T17:43:50","modified_gmt":"2026-07-13T17:43:50","slug":"attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1737","title":{"rendered":"Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh43TJKqVkJoN7Q3donw2FnXp1IrJEr6vvDteFOBCSR-PptAc8fMXXCq07kvKWoDacCHo6gi5-eUoX9mIBHggv-KXsoH31yBi0-_MZBjxYbiYNlhvAu8V_xhjuKHgnQj43x5S2pORBIGONxE_yLZdZOnDCmcjMegQjhwZtHDThg_4nlhZqwSizsMRCfZFQW\/s1700-e365\/ps-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.<\/p>\n<p>\u00abThe script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the enumeration attempt,\u00bb Huntress researchers Jevon Ang and Dray Agha <a href=\"https:\/\/www.huntress.com\/blog\/ai-coded-malware-vibe-coding-active-directory\" target=\"_blank\">said<\/a>.<\/p>\n<p>The attack chain involved the threat actor establishing Remote Desktop Protocol (RDP) access onto a domain-joined Windows Server with a set of pre-compromised credentials, followed by staging the tools in the \u00abC:\\ProgramData\\\u00bb folder. The incident took place in early June 2026.<\/p>\n<p>This included an artificial intelligence (AI)-generated payload to map the Active Directory environment. The assessment is based on various telltale signs, such as the prompt iteration title, placeholder strings, over-engineered code that features multiple methods to find a Domain Controller, and beautified console output using cyan, green, red, and yellow.<\/p>\n<p>Huntress described the bespoke PowerShell script as \u00abhighly aggressive\u00bb and \u00abnoisy,\u00bb making use of a \u00abfive-step cascading fallback mechanism\u00bb to enable reconnaissance and discovery. It&#8217;s titled \u00ab100% Working AD Information Gathering Script &#8211; FULLY FIXED,\u00bb suggesting a back-and-forth with a large language model (LLM).<\/p>\n<p>Once the primary Domain Controller is located, it initiates a data collection routine to systematically harvest AD users, computers, groups, organizational units (OUs), and trusts, and store the details in a staging directory.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>About 30 minutes later, the attacker moved to deploy a <a href=\"https:\/\/github.com\/peak\/s5cmd\" target=\"_blank\">s5cmd<\/a>, a legitimate tool used for bulk file operations, along with <a href=\"https:\/\/github.com\/mitchmoser\/SharpShares\" target=\"_blank\">SharpShares<\/a>, a C#-based network shares enumeration utility, to look for user-accessible data repositories.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>In the final stage, the data is said into CSV files, archived, and exfiltrated to a remote server, but not before creating an HTML file summarizing the data theft in the form of an Active Directory Inventory Report.<\/p>\n<p>\u00abIt&#8217;s likely a &#8216;helpful&#8217; inject from the LLM that the attacker simply went along with, rather than being intentionally authored into the script,\u00bb the researchers explained.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgBmmFR1cuGuh0l2g9YSpbvcSNDqY3yfiiJLGWxonWr4HWu8dk-SifDjpa1O1UK48CmgAd99kTH_XfSIk0jwL9sUHAhLxjwo9rwq2hy84klI01jDimB46YblHNf9JS1eLMOVE2cbBd1PUtRNWiDYoYWvrPC7joJCaTYP8ln2Qm6lFIUlSEr1r17LK2eG8r_\/s1700-e365\/ad.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgBmmFR1cuGuh0l2g9YSpbvcSNDqY3yfiiJLGWxonWr4HWu8dk-SifDjpa1O1UK48CmgAd99kTH_XfSIk0jwL9sUHAhLxjwo9rwq2hy84klI01jDimB46YblHNf9JS1eLMOVE2cbBd1PUtRNWiDYoYWvrPC7joJCaTYP8ln2Qm6lFIUlSEr1r17LK2eG8r_\/s1700-e365\/ad.png\" alt=\"\" border=\"0\" data-original-height=\"921\" data-original-width=\"1600\"\/><\/a><\/div>\n<p>The development is yet another sign that threat actors are augmenting their arsenal with vibe-coded malware generated with assistance from AI models, even if the technology isn&#8217;t being abused in ways not seen before. What it does change is that it lowers the barrier to entry for cybercrime, permitting less-skilled actors to come up with highly capable, evasive tooling with minimal effort.<\/p>\n<p>\u00abThe underlying attack chain still resembles the tried-and-tested smash-and-grab playbook we&#8217;ve seen for years,\u00bb Huntress said. \u00abThis core methodology has remained consistent, but it is now being selectively augmented by AI. This hybrid approach prioritises aggression and speed over stealth, allowing threat actors to execute highly damaging campaigns faster than ever.\u00bb<\/p>\n<h3>AI as a Force Multiplier<\/h3>\n<p>In a report published last week, Sygnia revealed that AI-enabled attackers do not necessarily need novel malware or zero-days, but that the real shift lies in the fact that cyber intrusions can be orchestrated at a speed and scale faster and bigger than defenders can contain them.<\/p>\n<p>The incident response company said it observed an AI-assisted cloud attack that progressed from initial access to broad compromise within a span of about 72 hours against a large Amazon Web Services (AWS)-based environment. The end goal of the activity is assessed to be financially motivated, with the attacker using the access to the victim&#8217;s cloud infrastructure for use as leverage for extortion.<\/p>\n<p>\u00abThe threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities,\u00bb it <a href=\"https:\/\/www.sygnia.co\/blog\/inside-an-ai-assisted-cloud-attack\/\" target=\"_blank\">said<\/a>. \u00abThe attack relied on familiar cloud techniques rather than novel malware or zero-days.\u00bb<\/p>\n<p>\u00abThe threat actor was not exploiting a single misconfiguration; they were chaining weaknesses across application services, AWS resources, source-control repositories, CI\/CD workflows, runtime components, and data stores, while rapidly executing credential discovery, secrets harvesting, cloud enumeration, deployment-pipeline abuse, runtime modification, database access, and operational disruption.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBxLQDy7VdLze43eMmpRllTXaPKPfB_veNUxQlqIu3-68GBJtegkhDGCqtaiSymOQviROdxln1FSd4zdMp5Jv9jeF1xQxLPc9uo9H7zW2nWHNax0wT0Y8JRj-zyUfbaCLqhxSfQT2sCfhWMBPL6UVgsh5RYVNVxwus_mW_BY9Ptwz3z7iF0_LWOnte-gqg\/s1600\/sy-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The attacker, per Sygnia, entailed repeated attempts to establish persistence on the compromised hosts, obtaining the access key to one of the AWS accounts through shortcomings in an internet-facing application. Each new access was followed by renewed enumeration, additional secret collection, persistence attempts by creating access keys and IAM users, and data exfiltration. At the same time, several attacker-created artifacts were masked as a pentest or a red teaming exercise.<\/p>\n<p>To further exert pressure on victims, the attacker performed a series of actions &#8211;<\/p>\n<ul>\n<li>Denying access to S3 buckets<\/li>\n<li>Limiting ECS services or containers to a maximum capacity of zero<\/li>\n<li>Creating ACL rules to block network access<\/li>\n<li>Purging SQS queues<\/li>\n<\/ul>\n<p>\u00abThe significance was not that AI introduced new attack techniques, as every observed action mapped to long-established adversary behaviors, but that it reduced the time and effort required to operationalize those techniques across a complex environment,\u00bb Sygnia pointed out.<\/p>\n<p>\u00abThe threat actor repeatedly converted newly obtained access into tailored action. For each new access key, the actor appeared to quickly determine the associated permissions, reachable resources, and most valuable next steps.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. \u00abThe script looked for the Domain Controller (DC)&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1738,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[64,2300,1887,1814,1934,2505,2195,2368],"class_list":["post-1737","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-active","tag-aigenerated","tag-attacker","tag-directory","tag-map","tag-powershell","tag-script","tag-suspected"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1737"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1737\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1738"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}