Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware
Hackers are exploiting the global interest in artificial intelligence (AI) to trick Windows users into downloading malware, according to the latest research from cybersecurity experts at FortiGuard Labs.
In one case spotted by researchers, cybercriminals were distributing a compressed folder disguised as a helpful AI technical guide. The folder was titled “Agentic Coding with Claude Code, The everyday developer’s guide to agentic coding with Claude Code.7z.” It looked completely safe at first glance, but it starts a complex chain of hidden scripts once opened.
Understanding the Multi-Stage Attack Chain
The attack begins when a victim opens a shortcut file (.lnk) inside the compressed archive. This file runs hidden commands using native Windows components like cmd.exe and findstr, and fetches data from files named 3th.pdf and 4th.pdf. that aren’t real documents but storage containers.
Now, the attack chain formally starts with a PowerShellscript that drops a secondary script into the...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE