logo

GenAI Writes Malicious Code to Spread AsyncRAT

ID: 060f2e9c-1034-563a-bb63-9dd05fe477fd

STIX ID: report--060f2e9c-1034-563a-bb63-9dd05fe477fd

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-26

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers from HP Wolf Security identified an email-based campaign employing generative AI to craft VBScript and JavaScript used to deploy the AsyncRAT remote access trojan; the attack used an AES-encrypted HTML attachment that led to a script chain (registry persistence, PowerShell injection, and process injection) to execute the payload. The findings show attackers are leveraging GenAI to lower the bar for creating effective malware and highlight the need for defenders to adopt AI-driven detection and pattern analysis to counter these evolving TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.