News · curated 13 Jul 2026
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration
First reported huntress.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The incident, documented by Huntress, shows attackers increasingly using LLMs to generate functional attack tooling like AD enumeration scripts, lowering the skill barrier and giving defenders new AI-authored artifacts to detect.
Huntress researchers Jevon Ang and Dray Agha reported a June 2026 intrusion in which an unknown threat actor used a suspected AI-generated ('vibe-coded') PowerShell script to enumerate Active Directory, mapping the domain controller, users, computers, and domains before exporting results and generating an AD_Report.html. The attacker gained RDP access to a domain-joined Windows Server with pre-compromised credentials and staged tooling in C:\ProgramData\.