FortiGuard Labs has analyzed a sophisticated multi-stage malware campaign that exploits AI hype by disguising malicious archives as AI-related documents (e.g., guides about Claude Code and PostgreSQL AI). The attack chain begins with a ZIP containing an LNK shortcut and hidden PDF files used as multi-zone payload containers. Execution flows through obfuscated PowerShell stages, AES-CBC decryption, XOR-based decoding, and AutoHotkey-based loaders that perform process hollowing to inject a .NET RAT and AsyncRAT into legitimate .NET Framework processes. Persistence is established via multiple scheduled tasks and VBS launchers disguised as Realtek audio components. Notably, the scripts contain Simplified Chinese variable names and unsanitized AI-generated comments, suggesting the threat actor used generative AI tools to accelerate development. The final payloads include a custom .NET RAT with remote desktop, process hollowing, and fileless assembly loading capabilities, plus AsyncRAT communicating with a hardcoded C2 IP. IOCs including C2 domains and file hashes are provided.

18m read timeFrom feeds.fortinet.com
Post cover image
Table of contents
The Initial ZIP with LNKThe Embedded PowerShell ScriptThe Dropped PowerShell ScriptDropped Scripts “RealtekAudioService64”AutoHotkey LoaderFinal Payload RATConclusionFortinet ProtectionsIOCs
144 Impressions