Cybercriminals Leverage AI-Generated Malicious Job Offers to Spread PureRAT Malware
ID: 26a7c939-a90e-5fd7-9f51-d478145efc75
STIX ID: report--26a7c939-a90e-5fd7-9f51-d478145efc75
Feed Name: GBHackers
A Vietnamese-linked actor is running an active phishing campaign that leverages AI-authored code and realistic job-themed lures to deliver PureRAT and HVNC payloads. The operation evolved from malicious attachments to Dropbox-hosted archives to evade filters, abuses legitimate applications for DLL sideloading, uses encrypted archives and loaders (batch/Python) with clear AI fingerprints, establishes persistence (Run key/scheduled tasks), and seeks corporate access likely for credential theft and resale on criminal marketplaces. Reported IOCs include sample archive and executable names, DLL filenames, the IP 196.251.86.145, and reusable passwords/GitLab handles linking to the operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
