Artificially intelligent malware launcher - aimal

dc.contributor.advisorÖzdemir, Enver
dc.contributor.authorShaqiri, Endrit
dc.contributor.authorID707241018
dc.contributor.departmentCybersecurity Engineering and Cryptography
dc.date.accessioned2026-08-14T06:39:48Z
dc.date.issued2026-04-04
dc.descriptionThesis (M.Sc.) -- Istanbul Technical University, Graduate School, 2026
dc.description.abstractModern antivirus (AV) and endpoint detection and response (EDR) systems increasingly rely on behavioral and machine-learning–based detection, significantly raising the bar for red team adversarial simulation and malware research. In response to this shift, we present AIMaL (Artificially Intelligent Malware Launcher), a self mutating red team evasion framework that integrates large language models (LLMs) to dynamically adapt malware execution and evasion strategies based on real-time detection feedback. AIMaL is designed to analyze whether detections are signature-based or behavior based and autonomously modify its internal logic accordingly. For signature-based detections, the system performs automated code morphing, junk code injection, and binary regeneration to invalidate static signatures. For behavior-based detections, AIMaL triggers an LLM-driven self-patching mechanism capable of rewriting existing evasion techniques or generating novel stealth execution paths informed by observed AV/EDR behavior. This feedback-driven loop enables continuous evolution of execution techniques, payload delivery, and runtime behavior without human intervention. The framework supports multiple process injection and execution techniques, encrypted payload delivery, and real-time code rewriting, allowing it to simulate advanced persistent threat (APT) like behavior in controlled environments. AIMaL is intended strictly for defensive research, red team exercises, and AV/EDR stress testing, providing security teams with a realistic platform to evaluate the resilience of modern detection systems against adaptive, AI-assisted threats. Additionally, AIMaL contributes to the broader field of AI-driven cybersecurity by demonstrating how autonomous code adaptation can be leveraged to systematically evaluate weaknesses in modern defensive systems. By enabling controlled experimentation with evolving attack techniques, the framework provides researchers and security practitioners with deeper insights into the limitations of current AV/EDR detection mechanisms and supports the development of more resilient, next-generation defensive technologies.
dc.description.degreeM.Sc.
dc.identifier.urihttps://hdl.handle.net/11527/78013
dc.language.isoeng
dc.publisherGraduate School
dc.sdg.typenone
dc.subjectBehavior-based detection
dc.subjectDavranışsal tabanlı tespit
dc.subjectAutonomous code adaptation
dc.subjectOtonom kod adaptasyonu
dc.subjectAutomated code morphing
dc.subjectOtomatik kod morflama
dc.titleArtificially intelligent malware launcher - aimal
dc.title.alternativeYapay zekâ destekli malware başlatıcısı aimal
dc.typeMaster Thesis

Dosyalar

Orijinal paket

Şimdi gösterimde1 - 1 of 1
Yükleniyor...
Küçük Resim
Adı:
707241018.pdf
Boyut:
1,35 MB
Format:
Adobe Portable Document Format

Lisans paketi

Şimdi gösterimde1 - 1 of 1
Yükleniyor...
Küçük Resim
Adı:
license.txt
Boyut:
1,58 KB
Format:
Item-specific license agreed upon to submission
Description: