# Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used to Map Active Directory Post-RDP Compromise

> A financially motivated threat actor used pre-compromised credentials to gain RDP access to a domain-joined Windows Server, then deployed a suspected AI-generated ("vibe-coded") PowerShell script, Untitled1.ps1, to enumerate Active Directory. The actor followed up roughly 30 minutes later with the legitimate tools s5cmd and SharpShares to enumerate and exfiltrate network share data as CSV/HTML/ZIP archives.

- **Published:** 2026-07-13T00:00:00Z
- **Last reviewed:** 2026-07-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1281
- **ID:** TL-2026-1281
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On June 3, 2026, Huntress incident responders identified an intrusion against a domain-joined Windows Server in which an unidentified, likely financially motivated threat actor used pre-compromised credentials to establish a Remote Desktop Protocol (RDP) session. After staging tools in C:\ProgramData, the actor deployed a PowerShell script named Untitled1.ps1 within minutes of gaining access. The script bore multiple hallmarks of AI/LLM ("vibe-coded") generation: an internal title of "100% Working AD Information Gathering Script - FULLY FIXED" consistent with iterative prompt refinement, an unedited placeholder hostname ("Server1.HR.local") left inside its Domain Controller discovery fallback logic, five redundant and cascading DC-discovery methods (DNS query, nltest, Active Directory PowerShell module, environment-variable inspection, and a hardcoded fallback) where one or two would normally suffice, heavily repetitive boilerplate try/catch error handling, and excessive, unnecessary colorized Write-Host console output (cyan, green, red, yellow).

The script systematically enumerated Active Directory users (in standard, email-enabled, and simplified formats), computers, groups, organizational units, domain trusts, and DNS-derived subnets, writing each category to CSV, generating an HTML summary report (AD_Report.html), and compressing all output into a timestamped ZIP archive under a directory named C:\AD_Reports_<datetime>. Approximately 30 minutes after the initial PowerShell-based enumeration, the actor deployed two additional, legitimate tools: s5cmd.exe (a high-performance, open-source Amazon S3 command-line utility, here abused for bulk exfiltration to attacker-controlled cloud storage rather than its intended AWS use case) and SharpShares.exe (an open-source, multithreaded C#/.NET assembly, github.com/mitchmoser/SharpShares, used to enumerate domain-accessible network shares and identify further data repositories for exfiltration).

Huntress researchers reconstructed the full script contents from Windows Event ID 4104 (PowerShell Script Block Logging) telemetry in the PowerShell Operational event log, since the script itself was deleted or otherwise unavailable for direct recovery, and noted that because the script was functionally unique to this intrusion, traditional hash- and signature-based antivirus detection was ineffective; detection instead relied on behavioral telemetry (sequential AD module calls, unusual CSV/ZIP creation in ProgramData, and abnormal PowerShell script-block volume). The case, publicly reported by Huntress and covered by The Hacker News, Cybersecurity News, Infosecurity Magazine, IT Security Guru, and Cyberpress on and around July 8, 2026, is notable not for a novel exploitation technique or CVE, but because it demonstrates that generative-AI/LLM assistance is measurably lowering the skill barrier and execution time for attackers to conduct competent Active Directory reconnaissance and share-based data theft, a trend separately highlighted in industry reporting on AI-enabled attacker speed and scale.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1087 Account Discovery
- T1087.002 Domain Account
- T1018 Remote System Discovery
- T1135 Network Share Discovery
- T1482 Domain Trust Discovery
- T1016 System Network Configuration Discovery
- T1010 Application Window Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1119 Automated Collection
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1027 Obfuscated Files or Information
- T1587 Develop Capabilities

## Sources

- [Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory](https://thehackernews.com/2026/07/attacker-uses-suspected-ai-generated.html)
- [AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration](https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory)
- [Hackers Using Vibe-Coded Generated PowerShell Script to Enumerate Active Directory Accounts](https://cybersecuritynews.com/vibe-coded-powershell-script-active-directory/)
- [Vibe-Coded Malware Caught in Active Directory Attack](https://www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/)
- [Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments](https://www.itsecurityguru.org/2026/07/08/huntress-uncovers-vibe-coded-malware-used-to-map-active-directory-environments/)
- [AI-Coded Malware Uses Vibe Coding to Map Active Directory Environments](https://cyberpress.org/ai-coded-vibe-coding-map-active-directory/)
- [Vibe-Coded Malware Caught in Active Directory Attack](https://www.socdefenders.ai/item/c4a2621f-433d-4807-aed8-ab545654bcad)
- [SharpShares (mitchmoser) - Multithreaded C# .NET Assembly to Enumerate Accessible Network Shares](https://github.com/mitchmoser/SharpShares)
- [s5cmd - High-Speed S3 CLI Tool for Bulk File Operations](https://s5cmd.com/)
- [Exposing Data Exfiltration: LOLBIN TTP Binaries](https://www.huntress.com/blog/exposing-data-exfiltration-lolbin-ttp-binaries)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1281
