A sophisticated malware campaign targeting niche Large Language Model (LLM) communities is leveraging advanced social engineering tactics to spread a dangerous Remote Access Trojan (RAT). The malware, dubbed “AI Waifu RAT” by security researchers, is presented as an innovative AI character augmentation tool that promises “meta” interactions between users and their virtual AI companions.
See also: Social Engineering: The Psychology Behind Attacks

The attack begins with a deceptively attractive proposition posted on LLM role-playing forums. The malicious actor presents its creation as a research project that allows users’ AI “Win11 Waifu” character to break the fourth wall and directly interact with their real computer systems. This marketing approach capitalizes on the community’s fascination with advanced AI capabilities and new interactions, presenting Arbitrary Code Execution (ACE) as a desirable feature rather than a critical security vulnerability.
The malware’s distribution method is a lesson in targeted social engineering, designed specifically to exploit the technical curiosity and trust within these niche communities. An analyst named Ryingo spotted the threat after discovering its active circulation and conducted an extensive technical analysis that revealed the true nature of this seemingly innocent “research project.” The malicious actor, who operates under multiple aliases such as KazePsi and PsionicZephyr, presents himself as a legitimate CTF (Capture The Flag) and cybersecurity researcher. However, the investigation does not reveal any credible evidence of his participation in legitimate security competitions or research.
Instead, their technical implementation demonstrates poor coding practices and rudimentary security knowledge that are inconsistent with genuine cybersecurity expertise. The AI Waifu RAT operates through a simple yet effective architecture. The malware creates a local HTTP server that listens on port 9999, creating a communication channel between the victim’s system and the interface controlled by the LLM. This design choice allows for seamless integration with online AI platforms while maintaining constant access to the infected machine.
See also: CoinDCX employee arrested for stealing $44 million

The RAT exposes three main command and control points that facilitate full system compromise. The /execute_trusted endpoint represents the most dangerous component, accepting plaintext JSON commands and executing them directly via PowerShell processes. This code snippet shows how the malware adds UTF-8 to the user-provided instructions before execution, allowing arbitrary command execution on the victim’s system. The /execute endpoint includes a superficial security prompt that can be completely bypassed using the trusted endpoint, rendering the protection mechanism ineffective. In addition, the /readfile endpoint allows full access to the file system, allowing data extraction and identification activities.
The malware’s persistence mechanism involves writing registry entries to ensure automatic startup, while its evasion techniques involve instructing users to disable antivirus software under the guise of eliminating “false positives.” This social engineering approach effectively defeats the primary layer of defense, allowing the malware to operate undetected on compromised systems.
See also: ShinyHunters behind Salesforce data theft at Qantas, Allianz Life, LVMH

Social engineering techniques rely on exploiting human psychology to extract confidential information or access systems and data. Rather than targeting technical weaknesses, they attack human weakness. A common technique is phishing , where the attacker sends fake emails or messages, pretending to be from a trusted organization, in order to convince the victim to give up personal data or click on a malicious link. Similar is spear phishing , which targets specific individuals with more personalized information. Social engineering remains one of the most effective attack methods because it exploits the weakest point of any system: the human factor.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
