AI
Published 2026-09-24
Verified 2026-09-27

Project Black: uncensored local LLM mutates LSASS dumper to bypass lab EDRs (AU research)

Project Black (Eddie Zhang, published 24 September 2026; Cyber Security News amplify 26 Sep) documents a red-team experiment: can an LLM produce an LSASS credential-dumping executable that evades modern EDR with limited human direction? Claude Opus 5 / Opus 4.8 / Sonnet 5 refused even under Anthropic’s Cyber Verification Program. Open-weight DeepSeek v4 Flash 0731 produced a working reflective minidump + XOR writer that pypykatz could parse, but still triggered EDR. Moving the same binary to a community-uncensored Qwen 3.8 27B model running locally on a dual-RTX-4090 hashcat rig — with only a request to make it “more stealthy” — returned a revised build that generated no detections on either of two lab EDRs (vendors unnamed). Without further prompts the model reduced process-spawn suspicion, lowered LSASS access masks, inserted randomised sleeps during minidump construction, changed output path/name, and scrubbed embedded strings. Author frames this as a defender warning: after admin foothold, EDR is less dependable if rented GPU time can iterate bypasses. Research / lab only — not an in-the-wild campaign. Primary: Project Black; wire: Cyber Security News.

Product
Windows LSASS credential dumping vs enterprise EDR (lab); DeepSeek v4 Flash / uncensored Qwen 3.8 27B local models
Versions
n/a (research technique / model behaviour demo; not a product CVE)
Exploited in Australia?
unknown
Patch to
No product patch — assume admin foothold + local uncensored LLM can iterate LSASS dumpers past signature/behaviour baselines; enforce least privilege and credential hygiene; monitor unusual LSASS handle access / minidump patterns; isolate hosts showing credential-dumping behaviour; do not treat EDR alone as sufficient post-compromise control

Primary: Project Black — Bypassing EDR with Local AI (Eddie Zhang, 24 Sep 2026) · Vendor: Project Black (AU) — research blog · Cyber Security News — Local AI modifies Windows credential dumper to bypass EDR (26 Sep 2026)

ai australia identity