Ire identifies another LOTUSLITE specimen
Microsoft Brian Caswell, Bob Fleck, Mike Walker, Sarah Smith
Microsoft's Project Ire, an AI agent for malware classification, identified a LOTUSLITE backdoor variant that shared behavioral patterns with known samples but had a different hash not flagged by major security vendors. The sample was detected by only 1 of 72 security vendors on May 28, rising to 7 of 70 by June 4, while CrowdStrike Falcon, SentinelOne, Sophos, and others still missed it. Ire's behavior-based analysis caught the variant through function-by-function reverse engineering without relying on signature matching, demonstrating how agentic analysis can identify malware that escapes traditional detection methods.
Why it matters
Project Ire examined a timely malware sample and determined its intent through reverse engineering—identifying LOTUSLITE characteristics even as most major EDR tools did not detect it. The post Ire identifies another LOTUSLITE specimen appeared first on Microsoft Research.
Related stories
Claude, Codex, and Hermes installed unowned code inside corporate networks
Ars Technica · 3 weeks ago ·
36
A troubling rogue AI incident shows why the U.K. AI Security Institute deserves greater scrutiny
Fortune ·
45
Microsoft built a prompt injection detector. Then it caught a phishing campaign instead.
The New Stack · 1 week ago ·
25