216.73.217.22

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

· Published 11/06/2026 18:31 · Modified 15/06/2026 19:16

Export JSON

Essential information

Published
11/06/2026 18:31
Modified
15/06/2026 19:16
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
ai-themed lures asyncrat autohotkey chinese threat actor multi-stage infection process hollowing reflective injection scheduled tasks
Tags
2026-06-11 ai-themed lures asyncrat autohotkey chinese threat actor multi-stage infection process-hollowing reflective injection scheduled tasks
Related entities
6 indicators, 6 observables, 19 techniques (mitre), 1 malware, 3 others

Description

A sophisticated malware campaign exploits growing interest in artificial intelligence by distributing malicious files disguised as AI-related learning resources and technical guides. The attack employs an exceptionally complex chain beginning with compressed archives containing LNK shortcuts and hidden PDF files. Through multiple layers of obfuscation involving PowerShell scripts, batch files, and loaders, the campaign establishes persistent access and deploys two distinct .NET Remote Access Trojans including . The intermediate scripts extensively use Simplified Chinese variable names and exhibit coding patterns suggesting AI-assisted development, with cultural references to Chinese mythology used as symbolic aliases for Windows API calls. The attack implements advanced techniques including , reflective DLL injection, and scheduled task persistence while actively disabling Windows Defender exclusions to facilitate execution.

External references