logo

Cybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT Malware

ID: e4e56d07-52c6-55ab-bdf3-9b25b8aef753

STIX ID: report--e4e56d07-52c6-55ab-bdf3-9b25b8aef753

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

...
...

Attackers are distributing booby-trapped AI learning materials that execute a staged, largely fileless chain (LNK files and hidden data offsets in PDF-named files powering PowerShell stages and AutoHotkey scripts) to deploy .NET payloads including AsyncRAT and a modular RAT (clay_Client). The campaign uses scheduled tasks disguised as Realtek services, process hollowing, and legitimate tools to stay stealthy; Fortinet recommends blocking unsanctioned scripting engines, tuning endpoint memory scanning, auditing scheduled tasks, and providing vetted AI resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.