Threat Actor Dark Factory (The Future of Al Hacking?) | The X-Ops Brief
A criminal talked commercial AI models past their guardrails. Then stood up a "company" of AI agents that engineered, tested and refined malware.
It began when Sophos analysts found a folder named "test" on an endpoint nobody recognised. Inside was the front end of a machine: Cobalt Strike profiles, a Telegram command channel, a hidden Sliver server behind Cloudflare and scripts written with the help of AI.
This is a look at one of the first known agentic AI cybercrime operations: how underground brokers sell access to frontier models for as little as $15, how jailbreaking has become professional criminal tradecraft, and how one operator orchestrated a team of AI agents: Coordinated through MCP, mapped to MITRE ATT&CK, to build nearly 80 payloads and test them against real EDR in a private lab.
Chapters:
Sources & further reading:
- Sophos X-Ops research:
- https://www.sophos.com/en-us/blog/pointing-a-cursor-at-evading-detection
- https://www.sophos.com/en-us/blog/ai-in-the-underground-curiosity-claims-and-concerns
- MITRE ATT&CK framework:
- https://attack.mitre.org
New investigations into AI Driven cybercrime monthly - Subscribe so you don't miss the next one.
#cybersecurity #AI #malware #threatintelligence