Breakglass Intelligence reported an active campaign using a custom AsyncRAT fork dubbed PhishingRAT, attributed to a Vietnamese-speaking cybercriminal operator. Investigators linked at least 12 samples built around lure themes including PhishingRAT, RobloxHack, and Spotify, and identified live, Cloudflare-fronted command-and-control infrastructure at alam[.]it[.]com, datadreamers[.]in[.]net, sc88[.]now, and indotech[.]it[.]com. The malware retained standard AsyncRAT capabilities such as keylogging, remote control, persistence via registry Run keys and scheduled tasks, and data exfiltration, while also adding HTTP flood functionality, aggressive persistence, and behavior intended to disable Microsoft Defender.
The campaign’s defining feature was a sandbox pollution engine that generated large volumes of fake malicious activity instead of simply terminating in analysis environments. Researchers observed simulated phishing POSTs, SQL injection, ransomware actions, credential theft, fake credit-card submissions, crypto-mining, port scanning, and other decoy behaviors designed to overwhelm PCAPs and automated detections while concealing genuine RAT traffic. Attribution was supported by multiple operational security failures, including a leaked Vietnamese-language debug PDB path, Debug builds, plaintext configuration data, weak hardcoded AES keys, reused mutexes, and the campaign label TestVT, suggesting repeated testing against VirusTotal.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Breakglass Intelligence published analysis of the PhishingRAT variant, highlighting a sandbox-confusion engine that generated fake malicious behaviors to pollute analysis, along with added HTTP flood, persistence, and Defender-disabling features. The report also cited OPSEC failures including a Vietnamese-language PDB path, Debug builds, weak AES keys, and the "TestVT" label, attributing the activity to a Vietnamese-speaking financially motivated operator with medium-to-high confidence.
A 38 KB .NET malware sample later identified as a modified AsyncRAT variant was recovered from MalwareBazaar. Analysis tied it to the same campaign and showed it used live C2 infrastructure over port 443.
Investigators observed an active AsyncRAT campaign between March 7 and March 10, 2026 using a custom fork dubbed "PhishingRAT." At least 12 samples were linked across PhishingRAT, RobloxHack, and Spotify lure themes, using Cloudflare-fronted C2 domains datadreamers[.]in[.]net, sc88[.]now, indotech[.]it[.]com, and live infrastructure at alam[.]it[.]com.
Breakglass reported that the command-and-control domain alam[.]it[.]com was freshly registered and moved behind Cloudflare, with no prior public threat intelligence reporting. This infrastructure change preceded later malware sample discoveries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.