A threat actor uses a malicious PowerShell script, likely created with the help of an AI system like ChatGPT , Gemini , or Microsoft's CoPilot, to push malware.
See also: Microsoft: Windows 10 WinRE update with BitLocker fixes

The malicious user used the script in an email campaign in March, targeting dozens of organizations in Germany to spread the Rhadamanthys malware .
AI-powered PowerShell develops infostealer
Researchers at cybersecurity firm Proofpoint attributed the attack to a malicious actor tracked as TA547, believed to be an initial access broker (IAB).
TA547, also known as Scully Spider, has been active since at least 2017, delivering a variety of malware for Windows (ZLoader/Terdot, Gootkit, Ursnif, Corebot, Panda Banker, Atmos) and Android (Mazar Bot, Red Alert) systems.
Recently, the malicious actor began using the modular stealer Rhadamanthys malware, which it promotes via a PowerShell AI, which is constantly expanding its data collection capabilities (cache, browser, cookies).
Proofpoint has been tracking TA547 since 2017 and said this campaign was the first where the threat actor was observed using Rhadamanthys malware.
See also: DEEP#GOSU malware campaign targets Windows users
The info stealer has been distributed since September 2022 to multiple cybercrime groups under the malware-as-a-service (MaaS).

According to researchers at Proofpoint, TA547 impersonated German cash-and-carry brand Metro in a recent phishing using invoices as a lure for “dozens of organizations across various industries in Germany.”
The messages included a password-protected ZIP file “MAR26,” which contained a malicious shortcut file (.LNK). Accessing the shortcut file enabled AI PowerShell to remotely execute the malware.
The researchers explain that this method allowed the malicious code to execute in memory without touching the disk. The researchers also note that these features are typical of code originating from production AI solutions such as ChatGPT, Gemini, or CoPilot.
While they cannot be absolutely certain that the PowerShell code came from a large language model (LLM) solution, the researchers say that the script content suggests the potential for TA547 to use genetic artificial intelligence to compose or rewrite the PowerShell script.
See also: FBI: More information on AvosLocker ransomware and protection tips
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What are the techniques for protecting against malware?
One of the most effective ways to protect against malware, such as the AI-generated PowerShell malware, is to use reliable security software. This should include a strong firewall and be able to detect and remove malware. Regularly updating your operating system and applications is another important protection technique. Updates often include security patches that can help protect your system from malware. Using strong and unique passwords is also critical to protecting against malware. Information security training can help you recognize and avoid phishing scams, which are a common method of distributing malware.
Source: bleepingcomputer
