Threat Actors Weaponize AI Hype to Deliver AsyncRAT
ID: 602bc8ae-3ef1-5b7b-842e-ceabc685992e
STIX ID: report--602bc8ae-3ef1-5b7b-842e-ceabc685992e
Feed Name: Fortinet Blog
#### Executive summary: FortiGuard Labs observed a sophisticated multi-stage malware campaign that uses malicious .lnk files inside archives masquerading as AI-related documents to trigger staged extraction (line-range containers), obfuscated PowerShell decryption, AutoHotkey loaders, and reflective/.NET in-memory RAT deployment (custom RAT and AsyncRAT). The chain establishes robust persistence (scheduled tasks, VBS chains), performs defense evasion (Defender exclusions, string/cmdlet obfuscation, process hollowing, assembly reflection), and includes actionable IoCs (IP 107.172.10.190, three domains, and multiple file hashes) and Fortinet detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
