Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitysearch-ad-manipulationai-enabled-threat-activitydefense-evasion-method

AI-Assisted Malware Campaign Distributed Through Fake Software Downloads

Updated 3mo agoFirst seen Mar 20, 20264 sources

Researchers reported a large-scale malware distribution campaign that used fake software offerings hosted on trusted platforms to infect users, with operators increasingly relying on AI-assisted or “vibe-coded” development to scale payload creation. McAfee identified more than 443 malicious ZIP archives masquerading as AI tools, game cheats, VPNs, drivers, and decryptors, distributed via services including Discord, SourceForge, FOSSHub, MediaFire, and mydofiles.com. The campaign used 48 variants of WinUpdateHelper.dll across 17 kill chains, each with separate command-and-control infrastructure but linked through shared cryptocurrency wallet credentials, allowing researchers to trace monetization activity and victim distribution across countries including the US, UK, India, Brazil, France, Canada, and Australia.

A separate but related report described another multi-stage malware campaign that also relied on deceptive delivery and evasion, using .NET Ahead-of-Time (AOT) compilation to hinder analysis and a host-scoring system to avoid sandboxes and low-value targets. In that intrusion chain, a phishing-delivered ZIP launched KeyAuth.exe, which fetched bound_build.exe and then deployed both the Rhadamanthys infostealer and an XMRig miner disguised as MicrosoftEdgeUpdater. The malware checked conditions such as RAM, uptime, document count, and active antivirus processes, and terminated itself if the environment scored below a threshold, showing a deliberate effort to evade detection while maximizing successful infections.

Share:
AI-Assisted Malware Campaign Distributed Through Fake Software Downloads
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 3, 20263mo ago

Trend Micro details Rust dropper using Claude Code and TradeAI lures

On 2026-04-03, Trend Micro disclosed a malware campaign in which differently branded lure archives such as ClaudeCode_x64.exe and TradeAI.exe delivered the same Rust-compiled dropper. The malware masqueraded as a graphics driver updater, used XOR-encrypted strings and anti-analysis checks, and retrieved staging data from Pastebin and Snippet.host while supporting multiple execution modes.

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads | Trend Micro (US)
Mar 24, 20263mo ago

Netskope uncovers GitHub split-payload malware campaign

On 2026-03-24, Netskope disclosed a large-scale malware delivery campaign using more than 300 trojanized GitHub repositories posing as AI tools, game cheats, crypto bots, Roblox scripts, and VPN crackers. The operation used a custom LuaJIT-based trojan split into a legitimate runtime and an obfuscated encrypted script, with anti-analysis, geolocation checks, screenshot capture, and C2 communications aimed at ultimately deploying an infostealer.

GitHub-hosted malware campaign uses split payload to evade detection - Help Net Security
Mar 19, 20263mo ago

Researchers reveal environment-scoring anti-analysis feature

Howler Cell reported that the .NET AOT malware used an environment-scoring system that evaluated RAM, uptime, document count, and antivirus presence to distinguish real victims from sandboxes. If a host scored below 5, the malware terminated itself to reduce detection.

Howler Cell identifies .NET AOT malware campaign

Researchers at Howler Cell identified a new multi-stage malware campaign using .NET Ahead-of-Time compilation to complicate analysis and evade security tools. The infection chain began with phishing emails carrying malicious ZIP archives that launched KeyAuth.exe, which downloaded additional components including bound_build.exe, Crypted_build.exe, Rhadamanthys infostealer, and an XMRig miner disguised as MicrosoftEdgeUpdater.

Jan 1, 20266mo ago

Campaign deploys miners, stealers, and persistence mechanisms

After execution, the fake-software malware redirected victims to bogus dependency downloads while establishing persistence, generating dynamic command-and-control infrastructure, running fileless PowerShell payloads, and adding Windows Defender exclusions. McAfee found the campaign deployed CPU and GPU coin miners and, in some cases, delivered SalatStealer or Mesh Agent, with infections concentrated in the United States and several other countries.

McAfee identifies large fake-software malware campaign

In January 2026, McAfee identified a large-scale malware campaign distributing trojanized ZIP archives disguised as AI tools, game hacks, VPNs, drivers, and decryptors. The operation used a malicious DLL, WinUpdateHelper.dll, across 48 variants and 17 kill chains, with payloads hosted on trusted platforms such as Discord, SourceForge, FOSSHub, MediaFire, and mydofiles.com.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Affected products
2 linked
GithubDocker
Organizations
5 linked
KasperskyHackReadNetskopeGitHubHowler Cell
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.