logo

Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware

ID: 24007be9-b8ee-5712-b278-3ffc92912ecd

STIX ID: report--24007be9-b8ee-5712-b278-3ffc92912ecd

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Deeba Ahmed

...
...

FortiGuard Labs reported a multi-stage Windows malware campaign that tricks users with AI-themed compressed guides; a malicious .lnk triggers PowerShell scripts that decrypt and drop payloads, add Defender exclusions, abuse AutoHotkey renamed as a legitimate service, and use process hollowing to deploy two RATs (a modular .NET client and AsyncRAT) while showing decoy documents. Researchers note signs of generative AI assistance in the code and warn organizations to monitor for suspicious shortcut files and scheduled tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.