← Back to Feed

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

June 11, 2026 · Fortinet Threat Research · Severity: HIGH

Cybercriminals are exploiting public interest in artificial intelligence to distribute malware, according to FortiGuard Labs. The campaign involves multi-stage attacks where victims are tricked into opening fake AI-themed documents, which then execute hidden PowerShell scripts. These scripts use AutoHotkey loaders and process injection techniques to deploy AsyncRAT, a remote access trojan that gives attackers full control over compromised systems. The attack targets individuals and organizations lured by AI-related content, potentially compromising sensitive data and systems. AsyncRAT enables persistent remote access, allowing threat actors to steal credentials, monitor activities, and deploy additional malware. This campaign highlights how cybercriminals capitalize on trending topics like AI to increase the success rate of social engineering attacks, emphasizing the need for vigilance when handling unsolicited documents or downloads.

FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.

      

Key Takeaways

  • FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell.
  • FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.
☕ Buy a Coffee