logo

PureRAT: Attacker Now Using AI to Build Toolset

ID: 07345ef1-74c5-5b03-ac15-f15f9c5cdf10

STIX ID: report--07345ef1-74c5-5b03-ac15-f15f9c5cdf10

Feed Name: security.com

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

This Symantec analysis describes an active phishing campaign attributed to a likely Vietnamese cybercriminal actor using AI-assisted tooling to develop scripts and payloads; lures impersonate job offers and deliver PureRAT, HVNC and other malware via malicious ZIP/RAR attachments or cloud-hosted downloads, often employing executable/DLL sideloading and persistent Python-based loaders. The report includes multiple commented code samples (batch and Python), infrastructure and hosting domains/IPs, numerous file hashes, and recommended mitigations and detections, and notes the actor may be selling access to compromised networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.