On January 24, the security agency

Deep Impersonation: AI-Generated Backdoor Scripts
The most conclusive evidence lies in comments like "# <– Your permanent project UUID" appearing in the script. Researchers point out that this wording is typical of AI tutorials or code generation prompts, designed to guide human users on how to customize placeholders. Hackers use AI to significantly increase the complexity of malicious scripts and improve development efficiency.

Attack Path: Targeting Cryptocurrency Assets
The attack begins with phishing links hosted on Discord. Once the victim clicks and runs the malicious shortcut file (LNK), a series of infection actions are triggered:
Persistence and Stealth: Creates a scheduled task that runs every hour, disguised as a OneDrive startup item.
Environment Detection: The malware checks hardware and user activity to ensure it does not run in a security analysis environment.
Asset Theft: Its ultimate goal is to gain infrastructure access, API credentials, and wallet private keys, thereby stealing cryptocurrency assets.

According to


