AI-Generated Scripts Used in Malicious Attack Chains

cyb3rops · x · 2026-07-19

A blog post detailing the recent tactical evolution of **TAG-150**, breaking down its infection chain across **DinDoor, DenoRAT, NightshadeC2**. The general attack chain unfolds as follows: - ClickFix / MSI induced execution - Triggers **AI-generated PowerShell** - Downloads and executes DinDoor and DenoRAT - Ultimately executes NightshadeC2 in memory via a Python loader The included screenshots showcase specifics of the PowerShell scripts, DenoRAT, NightshadeC2, and persistence mechanisms, highlighting how attackers string together multi-stage payloads with scripted execution.

Original post →

More from Safety

Safety channel →