Sophos researchers identified threat actors leveraging the Cursor IDE and Claude Opus to systematically develop and test endpoint detection and response (EDR) evasion techniques, with AI accelerating tool development while humans drove the strategic workflow. The framework combined AI-generated tools and scripts for malware development with human-driven engineering cycles to test bypass methods against Sophos, CrowdStrike, and Windows Defender agents, demonstrating how AI accelerates malware development while human oversight directs the objectives.