Threat Actors Weaponize AI Job Offers For PureRAT Infections

A Vietnamese threat actor is leveraging AI to craft sophisticated phishing tools in a campaign delivering PureRAT malware through fake job offers.

Security firms Trend Micro and Symantec have tracked the attacks, first spotted in December 2025.

The operation shows how AI lowers barriers for novice cybercriminals, enabling them to build complex malware loaders with detailed code comments and step-by-step instructions.

Phishing Lures Target Job Seekers

Attacks kick off with emails posing as job opportunities from companies like OPPO, Samsung, Duolingo, and Henkel.

Early variants used malicious ZIP or RAR attachments, per Trend Micro. Recent Symantec samples host files on Dropbox, with links urging downloads.

Filenames mimic legitimate documents, such as “New_Remote_Marketing_Opportunity_OPPO_Find_X9_Series.zip” and “Duolingo_Marketing_Skills_Assessment_oct.rar.”

Victims likely open these on work machines, hoping for employment leads. The broad targeting suggests cybercrime over espionage, possibly to steal corporate access for resale.

Opening the archive triggers DLL side-loading. Attackers repurpose tools like Haihaisoft PDF Reader, old Microsoft Excel, or Foxit PDF Reader.

Executables disguise as “Salary and Benefits Package.EXE” or “adobereader.exe.” Malicious DLLs named oledlg.dll, msimg32.dll, version.dll, or profapi.dll load batch scripts.

These scripts scream AI generation. One example hides in %LOCALAPPDATA%\Google Chrome, renames local “document.pdf” and “document.docx” to “huna.zip” and “huna.exe,” extracts with password “huna@dev.vn,” and runs zvchost.exe Python payload from http://196.251.86[.]145/huna2.

It adds persistence via Run key as “ChromeUpdate,” opens a decoy PDF, then restores originals. Vietnamese comments like “:: Tạo thư mục ẩn nếu chưa tồn tại” and numbered steps mark AI hallmarks.

A streamlined variant uses emojis in comments (“✅ Kiểm tra tồn tại,” “🔥 CHẠY VỚI WORKING DIRECTORY ĐÚNG”), a telltale AI trait from social media training data.

Python loaders for HVNC payloads follow suit, with numbered steps (# === STEP 1: Base64 shellcode ===), API constants, and notes like “#NHỚ dán shellcode base64 HVNC vào đây” (Remember to paste HVNC shellcode here).

They inject shellcode into suspended InstallUtil.exe processes.

Infrastructure rotates: hardcoded IPs, GitLab (gitlab[.]com/kimxhwan), Dropbox, and domains like ginten555333[.]com.

Clues point to Vietnam: @dev.vn passwords (“hwan@dev.vn,” “hwanxkiem@dev.vn”), reversed “Hwanxkiem” (Hoàn Kiếm district in Hanoi), and GitLab handle “kimxhwan.” “Huna” recurs in files and passwords, likely the actor’s handle.

The actor refines tools rapidly, chaining payloads like PureRAT and HVNC. Wide-net phishing aims for network footholds to sell on underground markets.

This fits emerging trends. Symantec’s recent whitepaper notes AI aids low-skill attackers in coding and automation. Detailed comments, debug messages, and instructions rarely appear in manual malware.

IOCs and Protections

Symantec lists hashes for batch scripts, DLLs, payloads, and benign lures like text2pdf.exe.

Update endpoints via Symantec Protection Bulletin. Block Dropbox links, scan archives, monitor %LOCALAPPDATA%\Google Chrome, and watch for AI-like comments in scripts. Train users on job scam red flags.

This campaign underscores AI’s dual edge: innovation for defenders, but easier crimes for threat actors. Vigilance against lure-based phishing remains key.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories