EBooks are popular, and their popularity lucrative threat actors the most, as they are widely shared digital assets that can easily circumvent security measures. Threat actors exploit users’ trust in seemingly harmless documents by embedding malware in eBook files or disguising malicious code as legitimate eBooks. ASEC researchers reported that AsyncRAT distribution is via multiple file extensions (.chm, .wsf, .lnk), with threat actors hiding the malware in apparently normal document files like questionnaires.
Source: GBHackers