Malware, AI/ML, Threat Intelligence

AI used in PureRAT malware campaign

AI-powered code has been leveraged by a Vietnamese threat actor to deliver PureRAT malware and other illicit payloads as part of a fake job phishing campaign initially discovered by Trend Micro in December, reports GBHackers News.

Malicious emails with job-themed lures have been used to redirect targets to Dropbox-hosted ZIP and RAR archives purporting to be for marketing, strategy, and project management roles in well-known brands, which contain illicit HR-related executables, according to an analysis from the Symantec and Carbon Black Threat Hunter Team. Running the executables sideloads DLLs that load nefarious AI-based batch scripts, which facilitate the deployment of PureRAT and HVNC payloads for remote credential compromise and lateral network movement.

Such batch scripts are believed to have been written using AI due to their presence of emojis in comments, a step-like structure, and clean error handling, said researchers, who recommended increased caution on unwanted job offers.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds