Threat reportMalwareTL-2026-1281
Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used to Map Active Directory Post-RDP Compromise
Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used (TL-2026-1281), also tracked as Vibe-Coded AD Enumeration Incident, is a medium-severity malware campaign, first published 2026-07-13. It has no confirmed attribution, affects Microsoft Windows Server (domain-joined, Active Directory), maps to 18 MITRE ATT&CK techniques (T1005, T1010, T1016), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1281
- Threat ID
- TL-2026-1281
- Also known as
- Vibe-Coded AD Enumeration Incident, Untitled1.ps1 Intrusion
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- unspecified
- Target regions
- Unknown
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used
Malware and tooling: Untitled1.ps1 (vibe-coded AD enumeration script), SharpShares, s5cmd
How Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used works
A financially motivated threat actor used pre-compromised credentials to gain RDP access to a domain-joined Windows Server, then deployed a suspected AI-generated ("vibe-coded") PowerShell script, Untitled1.ps1, to enumerate Active Directory. The actor followed up roughly 30 minutes later with the legitimate tools s5cmd and SharpShares to enumerate and exfiltrate network share data as CSV/HTML/ZIP archives.
On June 3, 2026, Huntress incident responders identified an intrusion against a domain-joined Windows Server in which an unidentified, likely financially motivated threat actor used pre-compromised credentials to establish a Remote Desktop Protocol (RDP) session. After staging tools in C:\ProgramData, the actor deployed a PowerShell script named Untitled1.ps1 within minutes of gaining access. The script bore multiple hallmarks of AI/LLM ("vibe-coded") generation: an internal title of "100% Working AD Information Gathering Script - FULLY FIXED" consistent with iterative prompt refinement, an unedited placeholder hostname ("Server1.HR.local") left inside its Domain Controller discovery fallback logic, five redundant and cascading DC-discovery methods (DNS query, nltest, Active Directory PowerShell module, environment-variable inspection, and a hardcoded fallback) where one or two would normally suffice, heavily repetitive boilerplate try/catch error handling, and excessive, unnecessary colorized Write-Host console output (cyan, green, red, yellow).
The script systematically enumerated Active Directory users (in standard, email-enabled, and simplified formats), computers, groups, organizational units, domain trusts, and DNS-derived subnets, writing each category to CSV, generating an HTML summary report (AD_Report.html), and compressing all output into a timestamped ZIP archive under a directory named C:\AD_Reports_<datetime>. Approximately 30 minutes after the initial PowerShell-based enumeration, the actor deployed two additional, legitimate tools: s5cmd.exe (a high-performance, open-source Amazon S3 command-line utility, here abused for bulk exfiltration to attacker-controlled cloud storage rather than its intended AWS use case) and SharpShares.exe (an open-source, multithreaded C#/.NET assembly, github.com/mitchmoser/SharpShares, used to enumerate domain-accessible network shares and identify further data repositories for exfiltration).
Huntress researchers reconstructed the full script contents from Windows Event ID 4104 (PowerShell Script Block Logging) telemetry in the PowerShell Operational event log, since the script itself was deleted or otherwise unavailable for direct recovery, and noted that because the script was functionally unique to this intrusion, traditional hash- and signature-based antivirus detection was ineffective; detection instead relied on behavioral telemetry (sequential AD module calls, unusual CSV/ZIP creation in ProgramData, and abnormal PowerShell script-block volume). The case, publicly reported by Huntress and covered by The Hacker News, Cybersecurity News, Infosecurity Magazine, IT Security Guru, and Cyberpress on and around July 8, 2026, is notable not for a novel exploitation technique or CVE, but because it demonstrates that generative-AI/LLM assistance is measurably lowering the skill barrier and execution time for attackers to conduct competent Active Directory reconnaissance and share-based data theft, a trend separately highlighted in industry reporting on AI-enabled attacker speed and scale.
MITRE ATT&CK techniques used in TL-2026-1281
Collection
T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data
Discovery
T1010 Application Window Discovery; T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1087.002 Domain Account; T1135 Network Share Discovery; T1482 Domain Trust Discovery
Defense Evasion
T1027 Obfuscated Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1133 External Remote Services
Resource Development
Affected products and versions in Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used
- Microsoft — Windows Server (domain-joined, Active Directory)
Vulnerable versions: Any domain-joined Windows Server reachable via RDP with valid/compromised credentials - Microsoft — Active Directory Domain Services
Vulnerable versions: Any on-premises Active Directory forest reachable from a compromised domain-joined host
Remediation for Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used
Immediate actions
- Hunt for PowerShell Event ID 4104 script-block logs containing repeated Active Directory module calls, nltest invocations, or CSV/HTML export logic within a short time window
- Alert on creation of CSV, HTML, or ZIP files under C:\ProgramData or newly created C:\AD_Reports_<datetime> style directories
- Flag execution of s5cmd.exe or any AWS CLI-style binary from non-standard install paths, especially with sync/cp arguments targeting external buckets
- Flag execution of SharpShares.exe or any unsigned/unmanaged .NET assembly performing SMB share enumeration across the domain
- Rotate and audit any RDP-exposed credentials, especially where RDP is reachable without MFA or jump-host brokering
- Review RDP access logs for the affected Windows Server for anomalous logon times, source IPs, or geolocations
Workarounds
- Disable or tightly restrict direct RDP exposure to domain-joined servers pending MFA/jump-host enforcement
- Constrain PowerShell execution policy and enable AMSI/Constrained Language Mode on servers not requiring full scripting capability
Longer-term hardening
- Shift detection engineering from static hash/signature rules to behavioral analytics for AD enumeration and mass file-export activity, since AI-generated scripts are functionally unique per-incident
- Enforce MFA and/or RDP gateway/jump-host brokering for all remote administrative access to domain-joined servers
- Deploy tiered administration and reduce standing domain-admin exposure on internet- or VPN-reachable RDP hosts
- Enable and centrally forward PowerShell Script Block Logging (Event ID 4104) and Module Logging across all domain-joined hosts
- Restrict outbound network access from servers to cloud storage endpoints (S3, Azure Blob, etc.) via egress filtering/allow-listing
- Deploy EDR with behavioral detection tuned to AD reconnaissance patterns (bulk AD queries, share enumeration, mass CSV export) rather than static IOCs
Timeline of Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used
- Harvested AD and share-enumeration data (CSV/HTML/ZIP artifacts) is exfiltrated using s5cmd, abusing its legitimate Amazon S3 bulk-transfer capability to move data to attacker-controlled cloud storage.
- Approximately 30 minutes after the initial PowerShell enumeration, the actor deploys s5cmd.exe and SharpShares.exe to enumerate accessible network shares and identify further data repositories.
- Untitled1.ps1 exports enumerated AD data to multiple CSV files, generates an HTML summary report (AD_Report.html), and compresses the output into a timestamped ZIP archive under C:\AD_Reports_<datetime>.
- Within minutes of RDP access, the actor executes the suspected AI-generated PowerShell script Untitled1.ps1 to discover the Domain Controller and enumerate AD users, computers, groups, OUs, trusts, and subnets.
- Threat actor establishes RDP session on a domain-joined Windows Server using pre-compromised credentials and stages tools in C:\ProgramData.
- Sygnia publishes separate research emphasizing that AI-enabled attackers do not require novel malware or zero-days, but instead achieve intrusions at markedly greater speed and scale.
- The Hacker News, Cybersecurity News, Infosecurity Magazine, IT Security Guru, and Cyberpress publish coverage of the Huntress findings.
- Huntress publishes 'AI-Coded Malware: Analyzing Vibe-Coded AD Enumeration,' reconstructing the full script from PowerShell Event ID 4104 script-block logging telemetry and detailing the AI-generation indicators.
Sources cited for Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used
- Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
- AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration
- Hackers Using Vibe-Coded Generated PowerShell Script to Enumerate Active Directory Accounts
- Vibe-Coded Malware Caught in Active Directory Attack
- Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments
- AI-Coded Malware Uses Vibe Coding to Map Active Directory Environments
- Vibe-Coded Malware Caught in Active Directory Attack
- SharpShares (mitchmoser) - Multithreaded C# .NET Assembly to Enumerate Accessible Network Shares
- s5cmd - High-Speed S3 CLI Tool for Bulk File Operations
- Exposing Data Exfiltration: LOLBIN TTP Binaries
Detection coverage for TL-2026-1281
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1281 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.