Threat Actors Distribute AsyncRAT via Fake AI Guides and Developer Tools (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Fake AI guides and dev tools used as initial lure
- Multi-stage chain uses LNK, PowerShell, AutoHotkey, and process hollowing
- Signs of AI-assisted coding in malware
- Recommendations: block AutoHotkey, memory scanning, monitor scheduled tasks
"A campaign uses booby-trapped files disguised as AI study guides and developer resources to deliver a multi-stage attack ending in the AsyncRAT trojan. Fortinet's FortiGuard Labs analysis describes files named "AI-Ready PostgreSQL 18" and a fake guide to agentic coding with Claude Code. The attack runs entirely through trusted system tools, using LNK, PowerShell, and AutoHotkey. Signs of AI-assisted coding were found in the malware."
no comments yet.