Censys published a threat overview tracing the AsyncRAT malware family from its 2019 open-source release into a multi-generation lineage of roughly 40 remote access trojan variants, with DCRAT identified as the most prolific descendant and additional forks including VenomRAT, Gh0stRAT, BitRAT, EchoRAT, LMTeamRAT, JasonRAT, Dumpling RAT, CyberSpike, DarkRAT, and Alfa Red Fox. The report says inherited TLS certificate metadata provides the most reliable way to connect these families, especially self-signed certificates on non-standard ports that use the pattern O=<Name> By <author>, L=SH, C=CN.
As of 16 June 2026, Censys had confirmed live command-and-control infrastructure for 13 variants, including about 49 AsyncRAT hosts, 36 DCRAT hosts, 21 Gh0stRAT hosts, and 18 VenomRAT hosts. The researchers said builder handles such as qwqdanchun and alexeikun appearing in certificate Subject and Issuer fields help link forks to shared development lineage, while name-based hunting is less dependable because labels such as PhoenixRAT, PegasusRAT, and MagnumRAT can overlap with legitimate or unrelated software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Censys ARC published a threat intelligence report mapping roughly 40 AsyncRAT-related variants across multiple generations of forks. The report identified inherited DCRAT TLS certificate metadata, especially the pattern "O=<Name> By <author>, L=SH, C=CN" on non-standard ports, as the strongest family-wide detection signal.
Censys searches confirmed live command-and-control infrastructure for 13 AsyncRAT-family variants, with the largest footprints observed for AsyncRAT, DCRAT, Gh0stRAT, and VenomRAT. The report also noted single-host or zero-host footprints for several lower-volume forks.
Censys reported that one rarer, fully rebranded Gh0stRAT certificate was first seen with subject CN=Gh0st RAT and issuer CN=Gh0st Server. The observation helped distinguish this AsyncRAT-lineage Gh0stRAT from the unrelated original Gh0st RAT family.
AsyncRAT, an open-source Windows remote access trojan, was first published on GitHub by the developer NYAN-x-CAT. Censys identifies this release as the starting point for a malware family that later expanded into dozens of forks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecensys.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.