AsyncRAT is a Windows remote-access trojan used across financially motivated cybercrime and espionage operations. It has been delivered through phishing and spear-phishing campaigns using password-protected archives, malicious shortcuts, document lures, cloud-hosted payloads, and trojanized installers. Observed delivery chains use script interpreters, PowerShell, signed Windows utilities, AutoIt-based loaders, WebDAV, and GitHub-hosted encrypted payloads to stage and execute the RAT while reducing detection.
Campaigns deploying AsyncRAT have established persistence through scheduled tasks and Startup-folder mechanisms, and have used encrypted shellcode loaders to inject the final payload into legitimate Windows processes. Some activity has executed customized AsyncRAT builds inside Windows Sandbox to evade host-based monitoring. AsyncRAT has also appeared in campaigns using DLL sideloading and in fake CAPTCHA social-engineering operations.
AsyncRAT has been associated with suspected Blind Eagle activity targeting Colombian and regional organizations, MirrorFace activity linked by multiple vendors to the Chinese APT10 cluster, and Operation GitPower, a North Korean Kimsuky espionage campaign targeting South Korean government, academic, diplomatic, military, security, and virtual-asset organizations. It has additionally been observed communicating with infrastructure controlled by the financially motivated Sable Squirrel operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
members of the VirusTotal community have linked it to exploitation of CVE-2022-30190, a Microsoft Support Diagnostic Tool (MSDT) vulnerability also known as Follina. Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT, and Qbot, which has previously delivered ransomware as a later-stage payload. | Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT (remote access trojan), and Qbot, which has previously delivered ransomware as a later-stage payload.
Its most consistently used malware payloads included vjw0rm, njRAT, Revenge RAT, Loda, and AsyncRAT.
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive. | CRIL has recently identified and analyzed a campaign that is actively distributing various types of malware, including Apanyan Stealer, Murk-Stealer, and AsyncRAT.
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT. Additionally... the malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT
33 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
По данным ESET, атакующие размещали на скомпрометированном хосте батник-файл, архиватор (например, 7-Zip) и заранее подготовленный архив с кастомизированной версией AsyncRAT, а затем запускали эту цепочку внутри сессии Windows Sandbox.
По данным ESET, атакующие размещали на скомпрометированном хосте батник-файл, архиватор (например, 7-Zip) и заранее подготовленный архив с кастомизированной версией AsyncRAT, а затем запускали эту цепочку внутри сессии Windows Sandbox.
A folder labelled Rats contained builds and artifacts linked to several remote-access tools, including AsyncRAT, DcRat, Remcos and XWorm. The IoCs also identify dccomicrat81[.]duckdns.org as an AsyncRAT command-and-control domain.
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Investigators linked the campaign to AsyncRAT payloads stored in repositories and described GitHub as both a delivery location and a command-and-control channel.
Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Users encounter a CAPTCHA page that mimics a legitimate human verification prompt, often while browsing seemingly harmless content websites.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
“A self-extracting archive launched VBScript and hidden PowerShell, wrote script content into ProgramData, then reached InstallUtil.exe.”
anc.wsf performs the following: Downloads vio.bat and xeno.bat... Executes vio.bat silently multiple times. Executes xeno.bat...
The attack uses legitimate Python downloads from official sources, establishing a complete Python environment on victim systems to execute sophisticated code injection techniques... python ne.py -i new.bin -k a.txt
members of the VirusTotal community have linked it to exploitation of CVE-2022-30190, a Microsoft Support Diagnostic Tool (MSDT) vulnerability also known as Follina.
We observed python.exe being used to perform code injection into explorer.exe... The ne.py Python script is used for Polymorphic Asynchronous Procedure Call (APC) Injection
When lyricalsync.mp3 is executed via mshta, it initiates a multistage deobfuscation process designed to evade detection mechanisms.
using double-extension files (.pdf.url) to deceive victims... This file poses as a PDF file using a double extension but is actually an internet shortcut file.
We observed python.exe being used to perform code injection into explorer.exe... The ne.py Python script is used for Polymorphic Asynchronous Procedure Call (APC) Injection
The ne.py Python script is used for Polymorphic Asynchronous Procedure Call (APC) Injection... defaults to injecting into the explorer.exe process if no parameter is provided.
a.txt contains keys used by ne.py to decrypt the obfuscated input binary file new.bin... new.bin serves as the primary input to ne.py, containing the main binary payload that is decrypted and injected into the target process
«Запуск wsb.exe - легитимная активность ОС, подписанный компонент Microsoft»; the scheduled task invoked `wsb.exe run --config ...\session.wsb`.
“[The chain] then reached InstallUtil.exe, a signed Windows utility that can be abused to run malicious code.”
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command.
rundll32.exe executes the DavSetCookie function from davclnt.dll with parameters specifying a WebDAV server... This is for downloading additional files from the remote server.
“Related samples contacted code repositories and cloud storage” and “The operation can move files between familiar services.”
2,265 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Customised remote-access trojan reportedly deployed by MirrorFace in a Windows Sandbox-based execution chain to conceal malicious activity from host-based security tooling.
Remote-access malware used to provide an operator with command-and-control access to compromised endpoints. In this campaign, an identified DuckDNS domain was associated with AsyncRAT C2.
Remote-access trojan delivered through a multi-stage SFX RAR/VBScript/PowerShell chain that abuses InstallUtil.exe and communicates with DuckDNS-based C2 infrastructure.
Remote-access trojan mentioned solely as a comparison for similar fake-installer and DLL-loading infection chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.