Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Threat Actors Using AI Generated Malicious Job Offers to Deploy PureRAT

Posted on January 29, 2026January 29, 2026 By CWS

A Vietnamese cybercrime group is utilizing synthetic intelligence to write down malicious code in an ongoing phishing marketing campaign that distributes the PureRAT malware by way of faux job alternatives.

The marketing campaign, initially detected in December 2025, represents a regarding evolution in menace actor capabilities, combining social engineering ways with machine-generated assault instruments to compromise organizations worldwide.

The assaults start with phishing emails disguised as reputable employment gives from well-known corporations. These messages comprise ZIP archives named after job-related subjects, resembling “New_Remote_Marketing_Opportunity_OPPO_Find_X9_Series.zip” or “Wage and Advantages Bundle.zip.”

When recipients open these archives, they set off an an infection chain that ultimately installs PureRAT or different malicious payloads like hidden digital community computing (HVNC) instruments.

The marketing campaign targets numerous organizations throughout a number of industries, suggesting the attackers could also be promoting entry to compromised networks moderately than conducting focused espionage.

After analyzing the assault instruments, Symantec researchers recognized a number of indicators that the malicious scripts have been created utilizing synthetic intelligence.

The batch information and Python code contained detailed Vietnamese-language feedback explaining every step, numbered directions, and even emoji symbols in code remarks—traits generally related to AI-generated programming.

This degree of documentation is never seen in manually written malware scripts, making the AI authorship notably evident.

The malicious archives sometimes comprise reputable executables repurposed for DLL sideloading assaults. Information resembling “adobereader.exe” or “Salary_And_Responsibility_Table.exe” are used to load dangerous DLLs together with oledlg.dll, msimg32.dll, model.dll, and profapi.dll.

These DLLs act as loaders for the ultimate payload, establishing persistence and sustaining stealth all through the an infection course of.

How PureRAT Establishes Persistence

As soon as executed, the malicious batch script creates a hidden listing underneath the Home windows %LOCALAPPDATApercentGoogle Chrome folder to hide its presence from customers.

The script then renames benign-looking information like “doc.pdf” and “doc.docx” into archive codecs, extracts the contents utilizing embedded compression instruments with the password “[email protected],” and executes a Python-based payload.

This payload fetches Base64-encoded malicious code from distant command-and-control servers operated by the attackers.

To keep up long-term entry, the malware provides itself to the Home windows Registry Run key underneath the identify “ChromeUpdate,” making certain it executes routinely each time the system begins.

After establishing persistence, the script opens a reputable PDF doc from the hidden listing to deceive victims into believing they merely opened a traditional file.

This method reduces suspicion and permits the malware to function undetected whereas stealing knowledge or offering distant entry to the compromised system.

The Vietnamese origin of the menace actor is obvious by way of a number of indicators past the language utilized in code feedback. Passwords containing “@dev.vn” domains and GitLab accounts with Vietnamese usernames reinforce the attribution.

Symantec Endpoint merchandise now detect and block the recognized malicious information, offering safety towards this evolving menace marketing campaign.

Observe us on Google Information, LinkedIn, and X to Get Extra On the spot Updates, Set CSN as a Most popular Supply in Google.

Cyber Security News Tags:Actors, Deploy, Generated, Job, Malicious, Offers, PureRAT, Threat

Post navigation

Previous Post: A Container Based Red Teaming Toolkit for AI Security Testing
Next Post: Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

Related Posts

Let’s Encrypt Unveils new “Generation Y” root and to 45 day certificates Cyber Security News
New ClickFix Campaign Hijacks Facebook Sessions Using Fake Verification Pages Cyber Security News
Hackers Weaponizing Calendar Files as a New Attack Vector Bypassing Traditional Email Defenses Cyber Security News
Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records Cyber Security News
What’s New With the Next-Generation AI Agent Cyber Security News
Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SolarWinds Patches Critical Web Help Desk Vulnerabilities
  • Cyber Insights 2026: Zero Trust and Following the Path
  • Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps
  • Threat Actors Using AI Generated Malicious Job Offers to Deploy PureRAT
  • A Container Based Red Teaming Toolkit for AI Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SolarWinds Patches Critical Web Help Desk Vulnerabilities
  • Cyber Insights 2026: Zero Trust and Following the Path
  • Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps
  • Threat Actors Using AI Generated Malicious Job Offers to Deploy PureRAT
  • A Container Based Red Teaming Toolkit for AI Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark