AI-Generated Scripts Used in Malicious Attack Chains
cyb3rops · x · 2026-07-19
A blog post detailing the recent tactical evolution of **TAG-150**, breaking down its infection chain across **DinDoor, DenoRAT, NightshadeC2**. The general attack chain unfolds as follows: - ClickFix / MSI induced execution - Triggers **AI-generated PowerShell** - Downloads and executes DinDoor and DenoRAT - Ultimately executes NightshadeC2 in memory via a Python loader The included screenshots showcase specifics of the PowerShell scripts, DenoRAT, NightshadeC2, and persistence mechanisms, highlighting how attackers string together multi-stage payloads with scripted execution.
More from Safety
- Model safety has become a real-world billion-dollar deployment problem — xuandongzhao · 2026-07-21
- AI recording devices should require disclosure, poster says, citing privacy asymmetry — AIandDesign · 2026-07-21
- Gary Marcus-backed “CERN for AI” pitch calls for an international frontier-model watchdog — GaryMarcus · 2026-07-21
- Judge approves Anthropic’s $1.5 billion copyright settlement, a U.S. record — Polymarket · 2026-07-21
- New MCP directory RepoAI scores servers on trust, auth, and dangerous tools — Low_Location1261 · 2026-07-21
- Sriram Krishnan says open-weight models are easier to secure because anyone can inspect them — pstAsiatech · 2026-07-21