{"rewrite":{"id":"r_43a8da951b743b406ce48628","clusterId":"c_89e6ae57e95cc73dd409b31e","slug":"fortinet-warns-of-asyncrat-campaign-disguised-as-ai-documents","model":"deepseek-v4-flash:free","headline":"Fortinet Warns of AsyncRAT Campaign Disguised as AI Documents","summary":"FortiGuard Labs has observed a campaign distributing AsyncRAT malware disguised as AI-related documents. The attack chain uses multi-stage scripts, including an AutoHotkey-based loader that reflectively injects a .NET remote access trojan and AsyncRAT into memory. The malware is distributed in a 7z archive disguised as a technical document, with hidden files and obfuscated commands targeting Windows users.","whyItMatters":"The campaign exploits growing interest in AI materials, using decoy documents and a complex multi-stage infection chain that suggests possible AI-assisted malware development.","webCardHtml":"\u003cp\u003eFortiGuard Labs has identified a new malware campaign that uses AI-themed decoy documents to lure victims. The attack begins with a 7z archive disguised as a technical guide, containing a shortcut file and hidden PDFs. The shortcut executes obfuscated Windows commands that extract specific lines from one of the PDFs, leading to a PowerShell staging script.\u003c/p\u003e\u003cp\u003eThe infection chain eventually deploys an AutoHotkey-based loader that reflectively injects a .NET remote access trojan and AsyncRAT into memory, enabling command-and-control communication. Notably, multiple intermediate scripts use Simplified Chinese variable names, and the code is organized, suggesting the threat actor may have used AI assistance in development.\u003c/p\u003e","blueskyPost":"FortiGuard Labs reports a new AsyncRAT campaign using AI-themed decoy docs. Multi-stage chain, hidden files, possible AI-assisted malware dev. Windows users beware.","twitterPost":"FortiGuard Labs: AsyncRAT campaign disguised as AI documents. Complex multi-stage attack, hidden files, possible AI-assisted malware development. Windows users targeted.","threadsPost":null,"newsletterBlurb":"FortiGuard Labs has uncovered a campaign distributing AsyncRAT malware disguised as AI-related documents. The attack uses a multi-stage infection chain with hidden files and obfuscated commands, possibly developed with AI assistance.","attributionJson":"[{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/422/4422277/?rss\",\"title\":\"Campaign distributing AsyncRAT malware disguised as AI-related documents\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4618,"outputTokens":503,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1786086131,"createdAt":"2026-08-07T06:53:57.000Z","publishedAt":"2026-08-07T06:56:44.000Z","updatedAt":"2026-08-07T06:53:57.000Z"},"cluster":{"id":"c_89e6ae57e95cc73dd409b31e","canonicalTitle":"AI関連文書を装ってマルウェア「AsyncRAT」を配信する攻撃キャンペーンを確認","representativeArticleId":"a_762be8eebed509e428428a5a","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"other\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-07-27T08:00:00.000Z","lastSeenAt":"2026-07-27T08:00:00.000Z","updatedAt":"2026-08-07T06:56:45.000Z"},"attribution":[{"source":"ASCII.jp","url":"https://ascii.jp/elem/000/004/422/4422277/?rss","title":"AI関連文書を装ってマルウェア「AsyncRAT」を配信する攻撃キャンペーンを確認"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"other","domain":"other","is_roundup":false},"keyFacts":null}
