Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fake AI study guide AsyncRAT lure campaign targeting Windows users

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A malware-luring campaign now uses fake AI study guides and developer resources to target Windows users at organizations, increasing the risk of stealthy AsyncRAT infections. The operation relies on staged execution and trusted system tools to avoid detection. Its AI-themed packaging is designed to exploit demand for learning material and trick professionals into opening malicious files.

Related Happenings

AI-generated PowerShell Active Directory reconnaissance script

Malware Activity
H score23 First: 09.07.2026 17:00 Last: 09.07.2026 17:00 Sources 1

About this happening: An AI-generated PowerShell script was used in a real Windows intrusion, showing how one-off malware can automate Active Directory reconnaissance and evade signature-ba...

Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints

Defensive Guidance
H score28 First: 08.07.2026 20:02 Last: 08.07.2026 20:02 Sources 1

About this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...

GhostTree and GhostBranch NTFS junction loops that evade recursive folder scanning

Technical Analysis
H score23 First: 16.06.2026 17:17 Last: 16.06.2026 17:17 Sources 1

About this happening: GhostTree and GhostBranch use recursive NTFS junction loops to generate effectively unlimited paths, allowing files in the same folder to evade EDR and Windows D...

AsyncRAT multi-stage delivery via trusted tools

Malware Activity
H score22 First: 11.06.2026 17:00 Last: 11.06.2026 17:00 Sources 1

How related: The manifest yields two .NET payloads: a modular remote access trojan (RAT) Fortinet tracks as clay_Client, and AsyncRAT, which beacons to its own command-and-control (C2) server.

About this happening: A Windows malware chain is now delivering AsyncRAT, increasing the risk of stealthy remote access on targeted systems. The lure uses AI study guides and develope...

AI as a C2 proxy abuse of Microsoft Copilot and xAI Grok browsing channels

Technical Analysis
H score24 First: 17.02.2026 20:08 Last: 17.02.2026 20:08 Sources 1

About this happening: Researchers disclosed AI as a C2 proxy, a technique that can turn Microsoft Copilot and xAI Grok browsing features into stealthy command-and-control relays, increa...

Timeline

  1. 11.06.2026 17:00 2 articles · 1mo ago

    Fake AI study guides deliver AsyncRAT to Windows users

    Initial Disclosure

    Threat actors disguise booby-trapped archives as AI study guides and developer resources to target Windows users at organizations, using a staged chain of LNK files, hidden documents, scheduled tasks disguised as Realtek audio services, AutoHotkey, and PowerShell to deploy AsyncRAT and a Fortinet-tracked RAT named clay_Client.

    Show sources