AI-Generated Scripts Used in Malicious Attack Chains
cyb3rops · x · 2026-07-19
A blog post detailing the recent tactical evolution of TAG-150, breaking down its infection chain across DinDoor, DenoRAT, NightshadeC2.
The general attack chain unfolds as follows:
- ClickFix / MSI induced execution
- Triggers AI-generated PowerShell
- Downloads and executes DinDoor and DenoRAT
- Ultimately executes NightshadeC2 in memory via a Python loader
The included screenshots showcase specifics of the PowerShell scripts, DenoRAT, NightshadeC2, and persistence mechanisms, highlighting how attackers string together multi-stage payloads with scripted execution.
More from Safety
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- a16z podcast: why 2-3 person startups are absent from policy debates — a16z Podcast · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11
- Class action accuses Anthropic of overselling Claude subscriptions with deceptive usage multipliers — The Decoder · 2026-09-11
- MD shows buying lab media requires background checks, calling AI bioweapon doom scenarios implausible — Ghost_Pilot_MD · 2026-09-11