Artificially intelligent malware launcher - aimal
Yükleniyor...
Dosyalar
Tarih
Yazarlar
Bölüm / Program
Cybersecurity Engineering and Cryptography
Dergi Başlığı
Dergi ISSN
Cilt Başlığı
Yayıncı
Graduate School
Türü
Özet
Modern antivirus (AV) and endpoint detection and response (EDR) systems increasingly rely on behavioral and machine-learning–based detection, significantly raising the bar for red team adversarial simulation and malware research. In response to this shift, we present AIMaL (Artificially Intelligent Malware Launcher), a self mutating red team evasion framework that integrates large language models (LLMs) to dynamically adapt malware execution and evasion strategies based on real-time detection feedback. AIMaL is designed to analyze whether detections are signature-based or behavior based and autonomously modify its internal logic accordingly. For signature-based detections, the system performs automated code morphing, junk code injection, and binary regeneration to invalidate static signatures. For behavior-based detections, AIMaL triggers an LLM-driven self-patching mechanism capable of rewriting existing evasion techniques or generating novel stealth execution paths informed by observed AV/EDR behavior. This feedback-driven loop enables continuous evolution of execution techniques, payload delivery, and runtime behavior without human intervention. The framework supports multiple process injection and execution techniques, encrypted payload delivery, and real-time code rewriting, allowing it to simulate advanced persistent threat (APT) like behavior in controlled environments. AIMaL is intended strictly for defensive research, red team exercises, and AV/EDR stress testing, providing security teams with a realistic platform to evaluate the resilience of modern detection systems against adaptive, AI-assisted threats. Additionally, AIMaL contributes to the broader field of AI-driven cybersecurity by demonstrating how autonomous code adaptation can be leveraged to systematically evaluate weaknesses in modern defensive systems. By enabling controlled experimentation with evolving attack techniques, the framework provides researchers and security practitioners with deeper insights into the limitations of current AV/EDR detection mechanisms and supports the development of more resilient, next-generation defensive technologies.
Tanım
Thesis (M.Sc.) -- Istanbul Technical University, Graduate School, 2026
Dergi veya Seri
ISSN
ISBN
Haklar
Anahtar Kelimeler
Behavior-based detection, Davranışsal tabanlı tespit, Autonomous code adaptation, Otonom kod adaptasyonu, Automated code morphing, Otomatik kod morflama