Fortinet Warns of AsyncRAT Campaign Disguised as AI Documents
The campaign exploits growing interest in AI materials, using decoy documents and a complex multi-stage infection chain that suggests possible AI-assisted malware development.
Reporting from 1 source: ASCII.jp.
FortiGuard Labs has observed a campaign distributing AsyncRAT malware disguised as AI-related documents. The attack chain uses multi-stage scripts, including an AutoHotkey-based loader that reflectively injects a .NET remote access trojan and AsyncRAT into memory. The malware is distributed in a 7z archive disguised as a technical document, with hidden files and obfuscated commands targeting Windows users.
FortiGuard Labs has identified a new malware campaign that uses AI-themed decoy documents to lure victims. The attack begins with a 7z archive disguised as a technical guide, containing a shortcut file and hidden PDFs. The shortcut executes obfuscated Windows commands that extract specific lines from one of the PDFs, leading to a PowerShell staging script.
The infection chain eventually deploys an AutoHotkey-based loader that reflectively injects a .NET remote access trojan and AsyncRAT into memory, enabling command-and-control communication. Notably, multiple intermediate scripts use Simplified Chinese variable names, and the code is organized, suggesting the threat actor may have used AI assistance in development.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.