Threat reportMalwareTL-2026-1152
AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for Active Directory Enumeration and S3 Exfiltration via s5cmd/SharpShares
AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for (TL-2026-1152), also tracked as Untitled1.ps1, is a medium-severity malware campaign, first published 2026-07-09. It has no confirmed attribution, affects Microsoft Active Directory Domain Services, maps to 23 MITRE ATT&CK techniques (T1016, T1018, T1021.001), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1152
- Threat ID
- TL-2026-1152
- Also known as
- Untitled1.ps1, AI-Coded AD Enumeration Incident, Vibe-Coded AD Malware
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- cross-sector
- Target regions
- Unknown
- Detection rules
- 9
- Indicators of compromise
- 20
How AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for works
Huntress observed a threat actor pivot via RDP with pre-compromised credentials, deploy an AI-generated ("vibe-coded") PowerShell script (Untitled1.ps1) to exhaustively enumerate Active Directory users, computers, groups, OUs, subnets, and trusts, then stage tools in C:\ProgramData\ and exfiltrate the collected data to Amazon S3 using the legitimate s5cmd.exe binary, alongside SharpShares.exe for network share enumeration.
On June 3, 2026, Huntress analysts Jevon Ang and Dray Agha identified and fully reconstructed a bespoke PowerShell script — internally titled "Untitled1.ps1" and self-labeled inside its own banner text as "100% Working AD Information Gathering Script - FULLY FIXED" — deployed by a threat actor who had gained RDP access to a victim environment using pre-compromised credentials (consistent with prior VPN/edge-device credential compromise).
The actor staged tooling directly in C:\ProgramData\, a common LOLBin/dual-use staging directory that blends with legitimate application data and frequently evades naive allow-list or reputation-based controls. Untitled1.ps1 was executed first and used a cascading, five-method fallback chain to identify the domain and the primary Domain Controller: DNS-based queries, nltest command invocation, the native ActiveDirectory PowerShell module, environment-variable inspection, and a hardcoded fallback value as a last resort. This degree of redundancy — attempting the same discovery goal five separate ways inside try/catch blocks — is atypical of human-authored tradecraft, where operators generally standardize on one or two proven methods to minimize noise and script size.
Once the DC was identified, the script systematically enumerated and exported the following AD objects to CSV inside a freshly created, timestamped directory (C:\AD_Reports_<datetime>): AD_Users.csv, AD_Computers.csv, AD_Groups.csv, AD_OUs.csv, AD_Subnets.csv, AD_Trusts.csv, AD_Users_With_Email.csv, AD_Simple_Users.csv, and DNS_Subnets.txt. The script then generated a self-referential HTML success report (AD_Report.html) summarizing the enumeration results, and finally compressed the entire output directory into a single archive for staged exfiltration.
Approximately thirty minutes after the AD enumeration completed, the actor deployed s5cmd.exe — a legitimate, high-performance, open-source command-line utility for interacting with Amazon S3 and S3-compatible object storage — into the same C:\ProgramData\ staging location and used it to transfer the compressed AD reconnaissance archive to an actor-controlled Amazon S3 bucket, entirely off traditional network egress channels that many organizations do not inspect or restrict (a technique previously documented by Huntress as a broader LOLBin exfiltration TTP and separately observed in Agenda/Qilin ransomware intrusions, where s5cmd was used to stage and exfiltrate data to cloud object storage ahead of encryption). In parallel, the actor ran SharpShares.exe, a publicly available multithreaded .NET share-enumeration assembly, deliberately filtering out common administrative shares ($C$, ADMIN$, IPC$) to instead surface user-facing and file-server share repositories more likely to contain sensitive data of value.
Huntress did not attribute the intrusion to any named actor or group, and no CVE, malware family, hash, domain, or IP indicator was published with the original advisory — the incident is notable purely for its tradecraft novelty: the first widely reported case of an intrusion using single-use, LLM ("vibe-coded") PowerShell tooling for full-spectrum AD reconnaissance. Huntress's SIEM detected the activity behaviorally, via Microsoft-Windows-PowerShell/Operational Event ID 4104 script-block logging, rather than through file-hash or static signature matching — the analysts explicitly noted the script "has never existed before and will likely never be compiled in this exact configuration again," making it fundamentally resistant to hash-based or YARA-style detection.
Multiple secondary indicators point to AI/LLM generation of the script rather than manual authorship: (1) the script's own title banner reads "100% Working AD Information Gathering Script - FULLY FIXED," language characteristic of iterative prompt-engineering and LLM self-correction cycles rather than deliberate human naming; (2) the script contains an unedited LLM placeholder value (an example/generic server name) that the operator failed to customize for the target environment, indicating low operator diligence or over-reliance on generated output; (3) redundant, over-engineered logic (five DC-discovery fallback methods where one or two would suffice) reflecting an LLM's tendency toward defensive/exhaustive code generation rather than efficient, minimal human coding style; (4) extensive cosmetic console output using colored Write-Host statements (cyan, green, red, yellow) for a non-interactive reconnaissance tool with no operational need for visual polish; and (5) unusually verbose, explanatory inline comments throughout the script, a hallmark of LLM code-generation output and atypical of hastily written offensive tooling.
This incident is significant for defenders because it demonstrates that generative-AI tooling has now measurably lowered the skill floor required to produce bespoke, evasive, single-use AD reconnaissance malware — a capability historically requiring PowerShell scripting proficiency. Huntress's core defensive recommendation is that signature and hash-based detection is structurally incapable of catching this class of threat, and that defenders must instead detect the underlying behavioral mechanics of AD enumeration (mass LDAP/ADSI queries, DC discovery chains, bulk CSV export of directory objects, and off-host cloud-storage-CLI network activity) rather than the surface syntax of any individual script.
MITRE ATT&CK techniques used in TL-2026-1152
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1069.002 Domain Groups; T1087 Account Discovery; T1087.002 Domain Account; T1135 Network Share Discovery; T1482 Domain Trust Discovery
Lateral Movement
T1021.001 Remote Desktop Protocol
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal
Exfiltration
T1030 Data Transfer Size Limits; T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage
Execution
Collection
T1074.001 Local Data Staging; T1119 Automated Collection; T1560.001 Archive via Utility
Initial Access
T1078 Valid Accounts; T1133 External Remote Services
Credential Access
Resource Development
Affected products and versions in AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for
- Microsoft — Active Directory Domain Services
Vulnerable versions: All supported versions
Fixed in: Not applicable (tradecraft/behavioral technique, not a software vulnerability) - Microsoft — Windows Remote Desktop Protocol (RDP)
Vulnerable versions: All supported versions
Fixed in: Not applicable (abused legitimate access via compromised credentials) - Amazon Web Services — Amazon S3
Vulnerable versions: Not applicable — abused as legitimate exfiltration destination
Fixed in: Not applicable
Remediation for AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for
Immediate actions
- Enable and centrally collect PowerShell Script Block Logging (Event ID 4104) and Module Logging across all endpoints and domain controllers
- Audit and restrict RDP access to domain controllers and hypervisors to jump-hosts/PAWs only, enforcing MFA on all remote-access paths
- Block or tightly control outbound network access to *.amazonaws.com and other cloud object-storage endpoints from endpoints that are not designated data-transfer hosts
- Alert on execution of s5cmd.exe, aws.exe, rclone.exe, and other cloud-storage CLI utilities from non-standard directories such as C:\ProgramData\
- Alert on process execution of files matching *sharpshares.exe or other share-enumeration tool signatures
- Rotate and audit all VPN/remote-access credentials suspected of prior compromise
Workarounds
- Restrict PowerShell execution policy and Constrained Language Mode on endpoints not requiring administrative scripting
- Deploy honeytoken AD accounts/objects to detect bulk enumeration activity
Longer-term hardening
- Deploy EDR/behavioral analytics tuned to detect AD enumeration patterns (mass LDAP queries, bulk CSV export of directory objects, DC discovery chains) independent of script hash or filename
- Implement application allow-listing (WDAC/AppLocker) restricting execution of unsigned or unapproved binaries from C:\ProgramData\ and other writable staging directories
- Deploy network egress monitoring/DLP capable of inspecting and alerting on large outbound transfers to cloud object storage APIs
- Establish a threat-hunting program specifically oriented around behavioral AD reconnaissance patterns rather than static IOC matching, given the rise of single-use LLM-generated tooling
- Harden and monitor VPN/edge devices, the most common initial-access vector preceding this class of intrusion
Timeline of AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for
- Huntress analysts Jevon Ang and Dray Agha fully reconstruct Untitled1.ps1 from captured Event ID 4104 script-block telemetry for analysis
- Huntress SIEM detects the activity behaviorally via Microsoft-Windows-PowerShell/Operational Event ID 4104 script-block logging telemetry, rather than via file-hash or static signature matching
- Actor uses s5cmd.exe to exfiltrate the compressed AD reconnaissance archive to an actor-controlled Amazon S3 bucket
- Approximately 30 minutes after AD enumeration, actor deploys s5cmd.exe into C:\ProgramData\ for Amazon S3 interaction
- SharpShares.exe executed to enumerate accessible network shares, deliberately filtering out common administrative shares
- Script generates AD_Report.html as a self-referential success/summary report and compresses the full output directory into an archive
- Script enumerates AD users, computers, groups, OUs, subnets, and trusts, exporting each object class to CSV inside a new timestamped directory C:\AD_Reports_<datetime>
- Untitled1.ps1 executed; script runs a five-method fallback chain (DNS, nltest, ActiveDirectory module, environment variables, hardcoded value) to identify the domain and primary Domain Controller
- Actor stages Untitled1.ps1 and supporting tooling in C:\ProgramData\ on the compromised host
- Threat actor establishes RDP access to victim environment using pre-compromised credentials, likely originating from prior VPN/edge-device compromise
- Incident receives broad security-media coverage (IT Security Guru, CyberPress, Infosecurity Magazine) as an early public example of AI/LLM-generated intrusion tooling
- Huntress publishes public blog analysis "AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration" disclosing the incident, script characteristics, and AI-generation indicators
Sources cited for AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for
- AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration
- Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments
- AI-Coded Malware Uses Vibe Coding to Map Active Directory Environments
- Vibe-Coded Malware Caught in Active Directory Attack
- Exposing Data Exfiltration: LOLBin TTP Binaries
- SharpShares: Multithreaded .NET Assembly to Enumerate Accessible Network Shares
- SharpShares (djhohnstein) - Enumerate all network shares in the current domain
- ShareFinder: How Threat Actors Discover File Shares
- Detecting the Presence of SharpShares Tool
Detection coverage for TL-2026-1152
As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1152 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.