<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Assisted-Attack on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-assisted-attack/</link><description>Recent content in Ai-Assisted-Attack on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 20 Jul 2026 13:16:24 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-assisted-attack/index.xml" rel="self" type="application/rss+xml"/><item><title>Russian Actor Uses Gemini CLI to Operate Dental Clinic Botnet</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-russian-speaking-hacker-uses-google-gemini-cli-to-control-bo/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-russian-speaking-hacker-uses-google-gemini-cli-to-control-bo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Demonstrates an emerging operational pattern where attackers use open-source AI CLIs to automate credential attacks and botnet management; no specific vulnerability to patch, but worth reviewing whether Gemini CLI or similar tools are present in CI/CD or developer environments and could be abused.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The session log analysis reveals AI-assisted password cracking and botnet C2 as concrete TTPs; build or tune detections for anomalous use of AI CLI tools (Gemini CLI, others) in endpoint and network telemetry, particularly subprocess chains or outbound API calls from unexpected processes.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates that commodity AI tooling is lowering the operational bar for solo threat actors; useful context for AI usage policy discussions and future board briefings on AI-enabled threats, but no immediate organizational action required given the small scale and no named sector targeting.&lt;/li>
&lt;/ul></description></item><item><title>Attacker Uses AI-Generated PowerShell Script for AD Enumeration</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-attacker-uses-suspected-ai-generated-powershell-script-to-ma/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-attacker-uses-suspected-ai-generated-powershell-script-to-ma/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No vulnerability to patch here — this is a reconnaissance TTP story showing adversaries using AI-generated scripts for AD discovery. Useful context for understanding how attacker tooling is evolving, but no configuration or software change required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The enumeration pattern — PowerShell querying DC, mapping users/computers/domains, exporting results to a directory, and generating AD_Report.html — is a detectable behavior signature; review PowerShell Script Block Logging coverage and build or tune a Sigma/KQL rule for this AD bulk-export pattern this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Demonstrates that AI tooling is lowering the skill floor for AD reconnaissance, a useful data point for board-level narratives about AI accelerating attacker capability; no immediate leadership action required.&lt;/li>
&lt;/ul></description></item></channel></rss>