Cybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT Malware
ID: e4e56d07-52c6-55ab-bdf3-9b25b8aef753
STIX ID: report--e4e56d07-52c6-55ab-bdf3-9b25b8aef753
Feed Name: Infosecurity Magazine (News)
Attackers are distributing booby-trapped AI learning materials that execute a staged, largely fileless chain (LNK files and hidden data offsets in PDF-named files powering PowerShell stages and AutoHotkey scripts) to deploy .NET payloads including AsyncRAT and a modular RAT (clay_Client). The campaign uses scheduled tasks disguised as Realtek services, process hollowing, and legitimate tools to stay stealthy; Fortinet recommends blocking unsanctioned scripting engines, tuning endpoint memory scanning, auditing scheduled tasks, and providing vetted AI resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
