Threat Actors Weaponize AI Hype to Deliver AsyncRAT
June 11, 2026 · Fortinet Threat Research · Severity: HIGH
FortiGuard Labs uncovered a malware campaign exploiting AI hype to distribute AsyncRAT, a remote access trojan. Attackers lure victims with fake AI-themed documents, which trigger hidden PowerShell scripts to download AutoHotkey loaders. These loaders then inject AsyncRAT into legitimate processes, enabling persistent remote control. The campaign targets organizations and individuals seeking AI tools, capitalizing on heightened interest in the technology. AsyncRAT allows attackers to steal data, execute commands, and monitor systems. The use of AI-themed lures increases the likelihood of successful infections, as victims are more likely to open seemingly relevant files. This highlights the growing trend of threat actors leveraging popular trends to enhance social engineering tactics. Organizations should remain vigilant against suspicious documents and enforce strict PowerShell execution policies to mitigate such threats.
FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.
Key Takeaways
- FortiGuard Labs identified a multi-stage malware campaign using fake AI-themed documents to deliver AsyncRAT.
- The attack chain uses hidden PowerShell scripts, AutoHotkey loaders, and process injection techniques.
- Threat actors are exploiting AI hype to trick users into installing remote access trojans.