GenAI Writes Malicious Code to Spread AsyncRAT
ID: 060f2e9c-1034-563a-bb63-9dd05fe477fd
STIX ID: report--060f2e9c-1034-563a-bb63-9dd05fe477fd
Feed Name: Dark Reading
Date Published: 2024-09-26
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers from HP Wolf Security identified an email-based campaign employing generative AI to craft VBScript and JavaScript used to deploy the AsyncRAT remote access trojan; the attack used an AES-encrypted HTML attachment that led to a script chain (registry persistence, PowerShell injection, and process injection) to execute the payload. The findings show attackers are leveraging GenAI to lower the bar for creating effective malware and highlight the need for defenders to adopt AI-driven detection and pattern analysis to counter these evolving TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
