AsyncRAT AI Lures Target Users Hunting AI Skills
ID: 6502600a-7ba9-5cd8-9edc-60f53c386371
STIX ID: report--6502600a-7ba9-5cd8-9edc-60f53c386371
Feed Name: securityonline.info
FortiGuard Labs details an active AsyncRAT campaign that uses AI-themed booby-trapped 7z archives containing shortcuts and hidden PDFs to stage layered PowerShell and AutoHotkey loaders, reconstruct and inject a .NET RAT via process hollowing, establish redundant scheduled-task persistence, and evade Microsoft Defender (including adding exclusions); the report includes technical TTPs and IOCs (notably C2 107.172.10.190) and recommends auditing shortcuts, scheduled tasks, PowerShell activity, and outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
