Threat Actors Weaponize AI Hype to Deliver AsyncRAT

June 15, 2026, 7:16 p.m.

Description

A sophisticated malware campaign exploits growing interest in artificial intelligence by distributing malicious files disguised as AI-related learning resources and technical guides. The attack employs an exceptionally complex multi-stage infection chain beginning with compressed archives containing LNK shortcuts and hidden PDF files. Through multiple layers of obfuscation involving PowerShell scripts, batch files, and AutoHotkey loaders, the campaign establishes persistent access and deploys two distinct .NET Remote Access Trojans including AsyncRAT. The intermediate scripts extensively use Simplified Chinese variable names and exhibit coding patterns suggesting AI-assisted development, with cultural references to Chinese mythology used as symbolic aliases for Windows API calls. The attack implements advanced techniques including process hollowing, reflective DLL injection, and scheduled task persistence while actively disabling Windows Defender exclusions to facilitate execution.

Date

  • Created: June 11, 2026, 4:31 p.m.
  • Published: June 11, 2026, 4:31 p.m.
  • Modified: June 15, 2026, 7:16 p.m.

Indicators

  • 96b486bd7308ef3d6771360800f4c9b48b10697bd4cb69a8589b97b039377ecb
  • 61b7fa5a7186cbf73dbc1f03e6e6f6819f5eb1e630a001059d381114bda2f974
  • 7d6ee3c6ff8f70b1817aaec82aff1d2babe0b62cafef3975262644743afc0cb8

Additional Informations

  • shampoolagtto.com
  • shampobiskworld.nl
  • shamppocosmaticso.com