Threat reportMalwareTL-2026-1152

AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for Active Directory Enumeration and S3 Exfiltration via s5cmd/SharpShares

mediumACTIVE

AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for (TL-2026-1152), also tracked as Untitled1.ps1, is a medium-severity malware campaign, first published 2026-07-09. It has no confirmed attribution, affects Microsoft Active Directory Domain Services, maps to 23 MITRE ATT&CK techniques (T1016, T1018, T1021.001), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1152

Threat ID
TL-2026-1152
Also known as
Untitled1.ps1, AI-Coded AD Enumeration Incident, Vibe-Coded AD Malware
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
cross-sector
Target regions
Unknown
Detection rules
9
Indicators of compromise
20

How AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for works

Huntress observed a threat actor pivot via RDP with pre-compromised credentials, deploy an AI-generated ("vibe-coded") PowerShell script (Untitled1.ps1) to exhaustively enumerate Active Directory users, computers, groups, OUs, subnets, and trusts, then stage tools in C:\ProgramData\ and exfiltrate the collected data to Amazon S3 using the legitimate s5cmd.exe binary, alongside SharpShares.exe for network share enumeration.

On June 3, 2026, Huntress analysts Jevon Ang and Dray Agha identified and fully reconstructed a bespoke PowerShell script — internally titled "Untitled1.ps1" and self-labeled inside its own banner text as "100% Working AD Information Gathering Script - FULLY FIXED" — deployed by a threat actor who had gained RDP access to a victim environment using pre-compromised credentials (consistent with prior VPN/edge-device credential compromise).

The actor staged tooling directly in C:\ProgramData\, a common LOLBin/dual-use staging directory that blends with legitimate application data and frequently evades naive allow-list or reputation-based controls. Untitled1.ps1 was executed first and used a cascading, five-method fallback chain to identify the domain and the primary Domain Controller: DNS-based queries, nltest command invocation, the native ActiveDirectory PowerShell module, environment-variable inspection, and a hardcoded fallback value as a last resort. This degree of redundancy — attempting the same discovery goal five separate ways inside try/catch blocks — is atypical of human-authored tradecraft, where operators generally standardize on one or two proven methods to minimize noise and script size.

Once the DC was identified, the script systematically enumerated and exported the following AD objects to CSV inside a freshly created, timestamped directory (C:\AD_Reports_<datetime>): AD_Users.csv, AD_Computers.csv, AD_Groups.csv, AD_OUs.csv, AD_Subnets.csv, AD_Trusts.csv, AD_Users_With_Email.csv, AD_Simple_Users.csv, and DNS_Subnets.txt. The script then generated a self-referential HTML success report (AD_Report.html) summarizing the enumeration results, and finally compressed the entire output directory into a single archive for staged exfiltration.

Approximately thirty minutes after the AD enumeration completed, the actor deployed s5cmd.exe — a legitimate, high-performance, open-source command-line utility for interacting with Amazon S3 and S3-compatible object storage — into the same C:\ProgramData\ staging location and used it to transfer the compressed AD reconnaissance archive to an actor-controlled Amazon S3 bucket, entirely off traditional network egress channels that many organizations do not inspect or restrict (a technique previously documented by Huntress as a broader LOLBin exfiltration TTP and separately observed in Agenda/Qilin ransomware intrusions, where s5cmd was used to stage and exfiltrate data to cloud object storage ahead of encryption). In parallel, the actor ran SharpShares.exe, a publicly available multithreaded .NET share-enumeration assembly, deliberately filtering out common administrative shares ($C$, ADMIN$, IPC$) to instead surface user-facing and file-server share repositories more likely to contain sensitive data of value.

Huntress did not attribute the intrusion to any named actor or group, and no CVE, malware family, hash, domain, or IP indicator was published with the original advisory — the incident is notable purely for its tradecraft novelty: the first widely reported case of an intrusion using single-use, LLM ("vibe-coded") PowerShell tooling for full-spectrum AD reconnaissance. Huntress's SIEM detected the activity behaviorally, via Microsoft-Windows-PowerShell/Operational Event ID 4104 script-block logging, rather than through file-hash or static signature matching — the analysts explicitly noted the script "has never existed before and will likely never be compiled in this exact configuration again," making it fundamentally resistant to hash-based or YARA-style detection.

Multiple secondary indicators point to AI/LLM generation of the script rather than manual authorship: (1) the script's own title banner reads "100% Working AD Information Gathering Script - FULLY FIXED," language characteristic of iterative prompt-engineering and LLM self-correction cycles rather than deliberate human naming; (2) the script contains an unedited LLM placeholder value (an example/generic server name) that the operator failed to customize for the target environment, indicating low operator diligence or over-reliance on generated output; (3) redundant, over-engineered logic (five DC-discovery fallback methods where one or two would suffice) reflecting an LLM's tendency toward defensive/exhaustive code generation rather than efficient, minimal human coding style; (4) extensive cosmetic console output using colored Write-Host statements (cyan, green, red, yellow) for a non-interactive reconnaissance tool with no operational need for visual polish; and (5) unusually verbose, explanatory inline comments throughout the script, a hallmark of LLM code-generation output and atypical of hastily written offensive tooling.

This incident is significant for defenders because it demonstrates that generative-AI tooling has now measurably lowered the skill floor required to produce bespoke, evasive, single-use AD reconnaissance malware — a capability historically requiring PowerShell scripting proficiency. Huntress's core defensive recommendation is that signature and hash-based detection is structurally incapable of catching this class of threat, and that defenders must instead detect the underlying behavioral mechanics of AD enumeration (mass LDAP/ADSI queries, DC discovery chains, bulk CSV export of directory objects, and off-host cloud-storage-CLI network activity) rather than the surface syntax of any individual script.

MITRE ATT&CK techniques used in TL-2026-1152

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1069.002 Domain Groups; T1087 Account Discovery; T1087.002 Domain Account; T1135 Network Share Discovery; T1482 Domain Trust Discovery

Lateral Movement

T1021.001 Remote Desktop Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal

Exfiltration

T1030 Data Transfer Size Limits; T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage

Execution

T1059.001 PowerShell

Collection

T1074.001 Local Data Staging; T1119 Automated Collection; T1560.001 Archive via Utility

Initial Access

T1078 Valid Accounts; T1133 External Remote Services

Credential Access

T1552 Unsecured Credentials

Resource Development

T1588.002 Tool

Affected products and versions in AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for

  • Microsoft — Active Directory Domain Services
    Vulnerable versions: All supported versions
    Fixed in: Not applicable (tradecraft/behavioral technique, not a software vulnerability)
  • Microsoft — Windows Remote Desktop Protocol (RDP)
    Vulnerable versions: All supported versions
    Fixed in: Not applicable (abused legitimate access via compromised credentials)
  • Amazon Web Services — Amazon S3
    Vulnerable versions: Not applicable — abused as legitimate exfiltration destination
    Fixed in: Not applicable

Remediation for AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for

Immediate actions

  • Enable and centrally collect PowerShell Script Block Logging (Event ID 4104) and Module Logging across all endpoints and domain controllers
  • Audit and restrict RDP access to domain controllers and hypervisors to jump-hosts/PAWs only, enforcing MFA on all remote-access paths
  • Block or tightly control outbound network access to *.amazonaws.com and other cloud object-storage endpoints from endpoints that are not designated data-transfer hosts
  • Alert on execution of s5cmd.exe, aws.exe, rclone.exe, and other cloud-storage CLI utilities from non-standard directories such as C:\ProgramData\
  • Alert on process execution of files matching *sharpshares.exe or other share-enumeration tool signatures
  • Rotate and audit all VPN/remote-access credentials suspected of prior compromise

Workarounds

  • Restrict PowerShell execution policy and Constrained Language Mode on endpoints not requiring administrative scripting
  • Deploy honeytoken AD accounts/objects to detect bulk enumeration activity

Longer-term hardening

  • Deploy EDR/behavioral analytics tuned to detect AD enumeration patterns (mass LDAP queries, bulk CSV export of directory objects, DC discovery chains) independent of script hash or filename
  • Implement application allow-listing (WDAC/AppLocker) restricting execution of unsigned or unapproved binaries from C:\ProgramData\ and other writable staging directories
  • Deploy network egress monitoring/DLP capable of inspecting and alerting on large outbound transfers to cloud object storage APIs
  • Establish a threat-hunting program specifically oriented around behavioral AD reconnaissance patterns rather than static IOC matching, given the rise of single-use LLM-generated tooling
  • Harden and monitor VPN/edge devices, the most common initial-access vector preceding this class of intrusion

Timeline of AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for

  • Huntress analysts Jevon Ang and Dray Agha fully reconstruct Untitled1.ps1 from captured Event ID 4104 script-block telemetry for analysis
  • Huntress SIEM detects the activity behaviorally via Microsoft-Windows-PowerShell/Operational Event ID 4104 script-block logging telemetry, rather than via file-hash or static signature matching
  • Actor uses s5cmd.exe to exfiltrate the compressed AD reconnaissance archive to an actor-controlled Amazon S3 bucket
  • Approximately 30 minutes after AD enumeration, actor deploys s5cmd.exe into C:\ProgramData\ for Amazon S3 interaction
  • SharpShares.exe executed to enumerate accessible network shares, deliberately filtering out common administrative shares
  • Script generates AD_Report.html as a self-referential success/summary report and compresses the full output directory into an archive
  • Script enumerates AD users, computers, groups, OUs, subnets, and trusts, exporting each object class to CSV inside a new timestamped directory C:\AD_Reports_<datetime>
  • Untitled1.ps1 executed; script runs a five-method fallback chain (DNS, nltest, ActiveDirectory module, environment variables, hardcoded value) to identify the domain and primary Domain Controller
  • Actor stages Untitled1.ps1 and supporting tooling in C:\ProgramData\ on the compromised host
  • Threat actor establishes RDP access to victim environment using pre-compromised credentials, likely originating from prior VPN/edge-device compromise
  • Incident receives broad security-media coverage (IT Security Guru, CyberPress, Infosecurity Magazine) as an early public example of AI/LLM-generated intrusion tooling
  • Huntress publishes public blog analysis "AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration" disclosing the incident, script characteristics, and AI-generation indicators

Sources cited for AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for

Detection coverage for TL-2026-1152

As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1152 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats