Threat actors are using fake AI study guides, developer tools, and other AI-themed decoys to infect Windows systems with a multi-stage malware chain that ends in AsyncRAT and a second remote access trojan tracked as clay_Client. Fortinet reported that victims receive booby-trapped archives containing a malicious .lnk file alongside hidden lure content; when opened, the shortcut launches a deeply staged sequence using PowerShell, VBS, scheduled tasks, repurposed AutoHotkey binaries, process hollowing, and reflective .NET loading while displaying a benign decoy document to reduce suspicion.
The campaign hides payload data inside files disguised as PDFs and masks persistence as Realtek or Windows audio diagnostic components, including scheduled tasks that resemble legitimate audio services. Researchers said the malware establishes command-and-control, gathers host information, and supports remote desktop and fileless execution, with observed infrastructure including shampobiskworld.nl, shampoolagtto.com, shamppocosmaticso.com, and 107.172.10.190. Fortinet also noted Chinese-language comments, mythology-based aliases, and other artifacts that may indicate AI-assisted malware development, and urged defenders to monitor PowerShell activity, audit scheduled tasks, scan memory, restrict unsanctioned scripting engines, and watch outbound connections for related indicators.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Fortinet assessed that Simplified Chinese variable names, unsanitized Chinese comments, emoji annotations, and aliases derived from Chinese mythology suggested likely AI-assisted malware development. Researchers said generative AI may have accelerated development while a human operator still defined the attack logic.
A separate branch extracted another PowerShell stage that added Microsoft Defender exclusions for C:\ and powershell.exe, re-enabled Windows Script Host, restored .vbs associations, and used a reflective .NET loader targeting cvtres.exe. The final .NET RAT was AsyncRAT, which created the mutex IDG5FUAM3PSONBSInGIGSWSD, contacted command-and-control domains including shampobiskworld.nl, shampoolagtto.com, and shamppocosmaticso.com, and supported remote access, screenshots, updates, self-delete, and fileless execution.
Fortinet found that renamed legitimate AutoHotkey binaries were used as execution engines for malicious scripts, including branches that reconstructed payloads from disguised data files. One branch used process hollowing into legitimate .NET binaries such as AddInProcess32.exe, AppLaunch.exe, or aspnet_compiler.exe to launch an obfuscated clay_Client RAT payload.
The intrusion established persistence with scheduled tasks masquerading as Realtek audio services, including CheckRealtekAudioVersion, RealtekAudioEnhancements64, and ResetRealtekAudioSettings64. It also used batch, PowerShell, and VBS components to relaunch itself hidden and maintain redundant persistence.
Opening the malicious LNK triggered an obfuscated command chain that extracted encrypted content from a PDF-named file, decrypted it with PowerShell, and executed successive stages while displaying a benign decoy document. The malware wrote staged payloads under a fake WindowsSoundDiagnostics path and used native Windows tools to stay stealthy.
FortiGuard Labs observed a malware campaign targeting Microsoft Windows systems using AI-themed lure documents and archives, including fake guides about PostgreSQL 18, marketing in the age of AI, and agentic coding with Claude Code. The campaign used a compressed archive containing a malicious LNK file and hidden files to begin a multi-stage infection chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.