Skip to content
AI used in PureRAT malware campaign

AI used in PureRAT malware campaign

Scworld January 30, 2026

AI-powered code has been leveraged by a Vietnamese threat actor to deliver PureRAT malware and other illicit payloads as part of a fake job phishing campaign initially discovered by Trend Micro in December, reports GBHackers News .

Malicious emails with job-themed lures have been used to redirect targets to Dropbox-hosted ZIP and RAR archives purporting to be for marketing, strategy, and project management roles in well-known brands, which contain illicit HR-related executables, according to an analysis from the Symantec and Carbon Black Threat Hunter Team. Running the executables sideloads DLLs that load nefarious AI-based batch scripts, which facilitate the deployment of PureRAT and HVNC payloads for remote credential compromise and lateral network movement.

Such batch scripts are believed to have been written using AI due to their presence of emojis in , a step-like structure, and clean error handling, said researchers, who recommended increased caution on unwanted job offers.

Extracted Entities

Attack Types (2)

Malware (2)

Tools (1)