Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware
ID: 24007be9-b8ee-5712-b278-3ffc92912ecd
STIX ID: report--24007be9-b8ee-5712-b278-3ffc92912ecd
Feed Name: HackRead
FortiGuard Labs reported a multi-stage Windows malware campaign that tricks users with AI-themed compressed guides; a malicious .lnk triggers PowerShell scripts that decrypt and drop payloads, add Defender exclusions, abuse AutoHotkey renamed as a legitimate service, and use process hollowing to deploy two RATs (a modular .NET client and AsyncRAT) while showing decoy documents. Researchers note signs of generative AI assistance in the code and warn organizations to monitor for suspicious shortcut files and scheduled tasks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
