Close Menu
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Trending

Defense Secretary Gilberto Teodoro Jr. on Saturday accused China of using threats and “disinformation through avoidance” after Beijing defended the arrest of more than 100 undocumented Filipino…

August 16, 2026

Russia’s Operation Matryoshka uses fake videos to target German election

August 15, 2026

Russia steps up its use of Ukrainian prisoners of war for propaganda purposes – Center for Countering Disinformation

August 15, 2026
Facebook X (Twitter) Instagram
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Subscribe
Web StatWeb Stat
Home»AI Fake News
AI Fake News

Cybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT Mal

News RoomBy News RoomJune 11, 2026Updated:June 11, 20264 Mins Read
Facebook Twitter Pinterest WhatsApp Telegram Email LinkedIn Tumblr

In our hyper-connected world, the hunger for professional growth has become a playground for cybercriminals. As artificial intelligence reshapes the tech landscape, developers and curious professionals are constantly hunting for the latest study guides, coding manuals, and AI-driven workflow tutorials. Threat actors have caught onto this trend, weaponizing our professional curiosity by disguising malicious software as legitimate “AI-ready” resources. According to new research from Fortinet’s FortiGuard Labs, hackers are now circulating deceptive files with names like “AI-Ready PostgreSQL 18” or fake agentic coding guides for tools like Claude Code. These aren’t just random viruses; they are sophisticated traps designed to compromise Windows environments by exploiting the very trust we place in educational content.

The brilliance of this attack lies in its “staged” execution, which keeps it hidden from traditional security software. When a victim opens one of these alluring study guides, they aren’t just opening a document; they are triggering a complex, silent chain of events. A malicious shortcut file kicks off a series of PowerShell scripts, which methodically pull hidden data from disguised files buried within the folder. While the user is shown a harmless decoy document to keep them from getting suspicious, the background process is hard at work, performing a series of decryption steps that would make a spy thriller plot look simple. To evade detection, the attackers use seemingly innocent tools—such as AutoHotkey—to run their malicious logic, effectively hiding in plain sight behind legitimate administrative software.

What makes this particular campaign so unsettling is how it mimics professional infrastructure to maintain persistence. Once the malware takes hold, it creates scheduled system tasks that masquerade as “Realtek audio services.” Because these look like standard driver components, most users—and even many automated security systems—would never think twice about them. The attack culminates in the deployment of AsyncRAT, a notorious remote access trojan that gives hackers a direct window into the victim’s machine. By using “process hollowing,” the attackers inject their malicious commands into a legitimate .NET process, ensuring that the malware’s activities appear to be coming from a trusted, system-authorized source rather than an intruder.

Researchers have noted a fascinating, albeit dark, trend in the construction of these attacks: they appear to be AI-assisted. Analysts identified code comments in Chinese and functions named after characters from Chinese mythology, suggesting that attackers are using generative AI to speed up the development of these exploits. While a human mastermind still directs the underlying logic of the attack, AI is being used to churn out the code, making the malware more modular and harder to predict. Industry experts describe this as “compositional opacity”—a technique where an attack is broken into small, seemingly harmless parts that only form a dangerous whole once they are already inside the target network.

The human element remains the most vulnerable part of our digital security, but responding to these threats requires a balance of better technology and smarter habits. Security professionals, such as Diana Kelley of Noma Security, emphasize that we must shift how we view downloads. We can no longer treat a PDF or a tutorial folder as “just a file”; we have to treat them as part of a software supply chain. Relying on random downloads from the internet, no matter how helpful they claim to be, is an increasing liability. Organizations should consider curating vetted internal libraries for AI resources, ensuring that employees have access to the knowledge they need without having to venture into the “wild west” of third-party websites.

Ultimately, defending against this “fileless” style of attack requires a layered approach that isn’t just focused on catching viruses, but on monitoring behavior. Experts suggest blocking unsanctioned scripting engines like AutoHotkey in professional environments, as they have little use for standard office work but high potential for abuse. Teams should also tune their endpoint security to scan memory, not just the files sitting on a hard drive, and keep a watchful eye on scheduled tasks or strange outbound network traffic. By auditing what our computers are doing behind the scenes and training our teams to recognize these specific AI-themed phishing lures, we can move from being passive targets to proactive defenders in an increasingly complex digital age.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
News Room
  • Website

Keep Reading

Kabogo warns media to brace for AI, fake news and misinformation ahead of 2027 general elections

The engineer teaching AI the difference between real and fake — TFN

The fake Forbes websites with AI content

No recruitment ongoing — NUPRC disowns fake, AI-generated employment letters

'Fake News': Elon Musk Denies Reports of Acquiring Israeli AI Company Decart – Haaretz

Janhvi Kapoor: Delhi High Court rules in the favour of Janhvi Kapoor as it orders removal of obscene content from 5000 pages on the internet, her plea covered allegedly pornographic, AI, fake content | Hindi Movie News

Editors Picks

Russia’s Operation Matryoshka uses fake videos to target German election

August 15, 2026

Russia steps up its use of Ukrainian prisoners of war for propaganda purposes – Center for Countering Disinformation

August 15, 2026

EU secures voluntary fact-checking pact with Meta and Tiktok after Ceuta crisis

August 15, 2026

The bizarre friendship of BIGBANG and T.O.P, and the cruel hope-torture [Lee Seung-hoon’s Obstacle]

August 15, 2026

Russia exploits Poland-Ukraine dispute to step up disinformation campaign, officials and experts say | WTVB | 1590 AM · 95.5 FM

August 15, 2026

Latest Articles

Disinformation Network Connects with Media, Politicians, and 560,000 ‘Bot’ and ‘Troll’ Accounts

August 15, 2026

Harassment and misinformation?: Ex-Cambridge professor at centre of plagiarism scandal found dead

August 15, 2026

Drone shot down over Latvia on August 14 could be false flag operation

August 15, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Facebook X (Twitter) Pinterest TikTok Instagram
Copyright © 2026 Web Stat. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.