PureRAT distributed through AI-assisted phishing emails
Malware Activity
Summary
Hide ▲
Show ▼
The PureRAT malware is being distributed through phishing emails that pose as job opportunities, expanding a threat that can steal data and preserve remote access on infected systems. It is a full-featured RAT and infostealer that first emerged last year. The malware’s scripts also show signs of AI-assisted code generation.
Related Happenings
AI-generated code is driving a rising CVE trend in March 2026
Trend
H score28
First: 26.03.2026 18:40
Last: 26.03.2026 18:40
Sources 1
About this happening:
AI-generated code is driving a rising CVE trend, with 35 disclosures in March 2026 showing a material increase in flaws across public advisories and open-source proj...
AI-generated code is driving a rising CVE trend in March 2026
TrendAbout this happening: AI-generated code is driving a rising CVE trend, with 35 disclosures in March 2026 showing a material increase in flaws across public advisories and open-source proj...
Arkanix Stealer infostealer operation
Malware Activity
H score29
First: 22.02.2026 17:33
Last: 22.02.2026 17:33
Sources 1
About this happening:
A short-lived Arkanix Stealer operation emerged in October 2025, putting browser data, wallets, and credentials at risk across multiple platforms. The project combined...
Arkanix Stealer infostealer operation
Malware ActivityAbout this happening: A short-lived Arkanix Stealer operation emerged in October 2025, putting browser data, wallets, and credentials at risk across multiple platforms. The project combined...
ChatGPT Mods token-stealing browser-extension campaign
Campaign
H score45
First: 30.01.2026 15:42
Last: 30.01.2026 15:42
Sources 1
About this happening:
The ChatGPT Mods campaign used 16 browser extensions to inject a content script into chatgpt[.]com, stealing authentication tokens that could let operators imperso...
ChatGPT Mods token-stealing browser-extension campaign
CampaignAbout this happening: The ChatGPT Mods campaign used 16 browser extensions to inject a content script into chatgpt[.]com, stealing authentication tokens that could let operators imperso...
PeckBirdy JScript C2 framework used across multiple environments since 2023
Malware Activity
H score21
First: 27.01.2026 11:01
Last: 27.01.2026 11:01
Sources 1
About this happening:
Since 2023, the PeckBirdy JScript-based C2 framework has been used by China-aligned APT actors to reach multiple environments, giving them flexible delivery an...
PeckBirdy JScript C2 framework used across multiple environments since 2023
Malware ActivityAbout this happening: Since 2023, the PeckBirdy JScript-based C2 framework has been used by China-aligned APT actors to reach multiple environments, giving them flexible delivery an...
Vampire Bot Go malware activity
Malware Activity
H score24
First: 07.10.2025 20:04
Last: 07.10.2025 20:04
Sources 1
About this happening:
BatShadow, a Vietnam-based threat group, is using phishing emails and ZIP archives to target job seekers and digital marketing professionals with Vampire...
Vampire Bot Go malware activity
Malware ActivityAbout this happening: BatShadow, a Vietnam-based threat group, is using phishing emails and ZIP archives to target job seekers and digital marketing professionals with Vampire...
Timeline
-
28.01.2026 14:10 2 articles · 5mo ago
PureRAT campaign analysis links AI-generated code to phishing delivery
Technical Analysis UpdateSymantec and the Carbon Black Threat Hunter Team analyzed a PureRAT campaign delivered through malicious links in phishing emails posing as job opportunities and found signs that the attackers used AI tools to write scripts and code, including emojis, explanatory comments, debug messages, and leftover instructions. The analysis also says the operator is likely based in Vietnam, citing Vietnamese language in the scripts and references to Hanoi.
Show sources
- Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign — www.infosecurity-magazine.com — 28.01.2026 14:10
- Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign — www.infosecurity-magazine.com — 28.01.2026 14:10