Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cybercriminals Leverage AI-Generated Malicious Job Offers to Spread PureRAT Malware

A Vietnamese threat actor is utilizing AI-generated code to conduct a phishing campaign aimed at delivering the PureRAT malware and related payloads. This campaign employs realistic job-themed lures to target corporate systems.

A Vietnamese threat actor is utilizing AI-generated code to conduct a phishing campaign aimed at delivering the PureRAT malware and related payloads. This campaign employs realistic job-themed lures to target corporate systems.

Initially documented by Trend Micro in December 2025, the campaign involved malicious ZIP and RAR attachments posing as job opportunity documents. Recent observations by Symantec indicate a shift in tactics, with phishing emails now directing victims to download archives from Dropbox. This approach is likely intended to bypass email security filters that are more vigilant with executable attachments from unknown sources.

This development illustrates how AI is reducing the barrier for less-skilled cybercriminals to create and automate attack chains using professional-looking tools. Typically, these emails impersonate roles in marketing, project management, or strategy, with filenames associated with well-known brands and corporate functions. Examples of these malicious archives include:

New_Remote_Marketing_Opportunity_OPPO_Find_X9_Series.zip Global_Ads_Strategy_Role_Summary.zip OPPO_FindX9_New_Product_Promotion_Plan.zip Advertising_and_Marketing_Henkel-AG_Smartwash.zip SAMSUNG_OLED_G5_Marketing_Dossier.zip Duolingo_Marketing_Skills_Assessment_oct.zip / .rar

Upon opening, these archives typically contain an executable that sideloads a malicious DLL. Legitimate software, such as Haihaisoft PDF Reader, older versions of Microsoft Excel, and renamed Foxit PDF Reader variants, is exploited as the sideloading host.

A Vietnamese threat actor is utilizing AI-generated code to conduct a phishing campaign aimed at delivering the PureRAT malware and related payloads.
Anna Fields · Thehackingpost

Executables are often disguised as HR-related files, such as Salary and Benefits Package.EXE or 2.Salary-benefits-bonus-KPIs(Job responsibilities).exe . The associated DLLs, such as oledlg.dll and profapi.dll , serve as loaders for malicious batch scripts.

These batch scripts, heavily commented in Vietnamese, suggest AI assistance. One script creates a hidden directory, renames files, and uses a bundled binary to extract encrypted content. It executes a Python interpreter with an inline command to fetch, decode, and run Base64-encoded payload code. Persistence is maintained through registry keys or scheduled tasks masquerading as ChromeUpdate .

A streamlined batch variant displays clear AI fingerprints, including a step-like structure and clean error handling.

Python loaders for deploying HVNC payloads reveal numbered sections and detailed debug output in both Vietnamese and English. The operation is linked to Vietnam through various indicators, including passwords and filenames referencing Vietnamese locations and handles.

Advertisement

The campaign's targeting and tools suggest a focus on financially motivated cybercrime rather than espionage. By luring jobseekers into opening malicious offers, the actor seeks initial access to corporate networks. PureRAT and HVNC payloads provide remote control for credential harvesting and lateral movement, potentially selling access to other actors on criminal marketplaces.

This campaign highlights the increasing risk of AI-assisted cybercrime, enabling convincing social engineering and sophisticated code generation by less-skilled actors. Organizations should treat unsolicited job offers, particularly involving external file hosting and executable documents, as high-risk. Ensuring that endpoint, email, and cloud controls are tuned to detect such behavior is critical.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories