# AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for Active Directory Enumeration and S3 Exfiltration via s5cmd/SharpShares

> Huntress observed a threat actor pivot via RDP with pre-compromised credentials, deploy an AI-generated ("vibe-coded") PowerShell script (Untitled1.ps1) to exhaustively enumerate Active Directory users, computers, groups, OUs, subnets, and trusts, then stage tools in C:\ProgramData\ and exfiltrate the collected data to Amazon S3 using the legitimate s5cmd.exe binary, alongside SharpShares.exe for network share enumeration.

- **Published:** 2026-07-09T00:00:00Z
- **Last reviewed:** 2026-07-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1152
- **ID:** TL-2026-1152
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On June 3, 2026, Huntress analysts Jevon Ang and Dray Agha identified and fully reconstructed a bespoke PowerShell script — internally titled "Untitled1.ps1" and self-labeled inside its own banner text as "100% Working AD Information Gathering Script - FULLY FIXED" — deployed by a threat actor who had gained RDP access to a victim environment using pre-compromised credentials (consistent with prior VPN/edge-device credential compromise).

The actor staged tooling directly in C:\ProgramData\, a common LOLBin/dual-use staging directory that blends with legitimate application data and frequently evades naive allow-list or reputation-based controls. Untitled1.ps1 was executed first and used a cascading, five-method fallback chain to identify the domain and the primary Domain Controller: DNS-based queries, nltest command invocation, the native ActiveDirectory PowerShell module, environment-variable inspection, and a hardcoded fallback value as a last resort. This degree of redundancy — attempting the same discovery goal five separate ways inside try/catch blocks — is atypical of human-authored tradecraft, where operators generally standardize on one or two proven methods to minimize noise and script size.

Once the DC was identified, the script systematically enumerated and exported the following AD objects to CSV inside a freshly created, timestamped directory (C:\AD_Reports_<datetime>): AD_Users.csv, AD_Computers.csv, AD_Groups.csv, AD_OUs.csv, AD_Subnets.csv, AD_Trusts.csv, AD_Users_With_Email.csv, AD_Simple_Users.csv, and DNS_Subnets.txt. The script then generated a self-referential HTML success report (AD_Report.html) summarizing the enumeration results, and finally compressed the entire output directory into a single archive for staged exfiltration.

Approximately thirty minutes after the AD enumeration completed, the actor deployed s5cmd.exe — a legitimate, high-performance, open-source command-line utility for interacting with Amazon S3 and S3-compatible object storage — into the same C:\ProgramData\ staging location and used it to transfer the compressed AD reconnaissance archive to an actor-controlled Amazon S3 bucket, entirely off traditional network egress channels that many organizations do not inspect or restrict (a technique previously documented by Huntress as a broader LOLBin exfiltration TTP and separately observed in Agenda/Qilin ransomware intrusions, where s5cmd was used to stage and exfiltrate data to cloud object storage ahead of encryption). In parallel, the actor ran SharpShares.exe, a publicly available multithreaded .NET share-enumeration assembly, deliberately filtering out common administrative shares ($C$, ADMIN$, IPC$) to instead surface user-facing and file-server share repositories more likely to contain sensitive data of value.

Huntress did not attribute the intrusion to any named actor or group, and no CVE, malware family, hash, domain, or IP indicator was published with the original advisory — the incident is notable purely for its tradecraft novelty: the first widely reported case of an intrusion using single-use, LLM ("vibe-coded") PowerShell tooling for full-spectrum AD reconnaissance. Huntress's SIEM detected the activity behaviorally, via Microsoft-Windows-PowerShell/Operational Event ID 4104 script-block logging, rather than through file-hash or static signature matching — the analysts explicitly noted the script "has never existed before and will likely never be compiled in this exact configuration again," making it fundamentally resistant to hash-based or YARA-style detection.

Multiple secondary indicators point to AI/LLM generation of the script rather than manual authorship: (1) the script's own title banner reads "100% Working AD Information Gathering Script - FULLY FIXED," language characteristic of iterative prompt-engineering and LLM self-correction cycles rather than deliberate human naming; (2) the script contains an unedited LLM placeholder value (an example/generic server name) that the operator failed to customize for the target environment, indicating low operator diligence or over-reliance on generated output; (3) redundant, over-engineered logic (five DC-discovery fallback methods where one or two would suffice) reflecting an LLM's tendency toward defensive/exhaustive code generation rather than efficient, minimal human coding style; (4) extensive cosmetic console output using colored Write-Host statements (cyan, green, red, yellow) for a non-interactive reconnaissance tool with no operational need for visual polish; and (5) unusually verbose, explanatory inline comments throughout the script, a hallmark of LLM code-generation output and atypical of hastily written offensive tooling.

This incident is significant for defenders because it demonstrates that generative-AI tooling has now measurably lowered the skill floor required to produce bespoke, evasive, single-use AD reconnaissance malware — a capability historically requiring PowerShell scripting proficiency. Huntress's core defensive recommendation is that signature and hash-based detection is structurally incapable of catching this class of threat, and that defenders must instead detect the underlying behavioral mechanics of AD enumeration (mass LDAP/ADSI queries, DC discovery chains, bulk CSV export of directory objects, and off-host cloud-storage-CLI network activity) rather than the surface syntax of any individual script.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1133 External Remote Services
- T1059.001 PowerShell
- T1087 Account Discovery
- T1087.002 Domain Account
- T1018 Remote System Discovery
- T1482 Domain Trust Discovery
- T1135 Network Share Discovery
- T1016 System Network Configuration Discovery
- T1069.002 Domain Groups
- T1033 System Owner/User Discovery
- T1074.001 Local Data Staging
- T1560.001 Archive via Utility
- T1119 Automated Collection
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1070 Indicator Removal
- T1021.001 Remote Desktop Protocol
- T1567.002 Exfiltration to Cloud Storage
- T1030 Data Transfer Size Limits
- T1537 Transfer Data to Cloud Account
- T1588.002 Tool
- T1552 Unsecured Credentials

## Sources

- [AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration](https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory)
- [Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments](https://www.itsecurityguru.org/2026/07/08/huntress-uncovers-vibe-coded-malware-used-to-map-active-directory-environments/)
- [AI-Coded Malware Uses Vibe Coding to Map Active Directory Environments](https://cyberpress.org/ai-coded-vibe-coding-map-active-directory/)
- [Vibe-Coded Malware Caught in Active Directory Attack](https://www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/)
- [Exposing Data Exfiltration: LOLBin TTP Binaries](https://www.huntress.com/blog/exposing-data-exfiltration-lolbin-ttp-binaries)
- [SharpShares: Multithreaded .NET Assembly to Enumerate Accessible Network Shares](https://github.com/mitchmoser/SharpShares)
- [SharpShares (djhohnstein) - Enumerate all network shares in the current domain](https://github.com/djhohnstein/SharpShares)
- [ShareFinder: How Threat Actors Discover File Shares](https://thedfirreport.com/2023/01/23/sharefinder-how-threat-actors-discover-file-shares/)
- [Detecting the Presence of SharpShares Tool](https://www.manageengine.com/log-management/correlation-rules/sharpshares-tool.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1152
