Security researchers reported that AsyncRAT and QuasarRAT continue to appear in real-world intrusions as commodity remote access trojans, with many operators relying on default or poorly customized configurations that leave recognizable forensic artifacts. Analysis highlighted recurring indicators including common C2 ports, predictable mutex naming, persistence mechanisms, and dropped plugin DLLs for AsyncRAT, while QuasarRAT samples were also tied to a default C2 port, a consistent mutex format, persistence behavior, and a hard-coded user-agent string.
Defenders were advised that these operational shortcuts create practical hunting opportunities across enterprise environments, especially because both malware families are open-source or long-established tools that remain effective when organizations fail to detect known threats. Supporting technical reporting on AsyncRAT and broader adversary infrastructure trends reinforced that investigators can use endpoint and threat intelligence tooling such as Velociraptor, ThreatFox, and THOR Scanner to identify infected hosts and trace related infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
COLCERT's referenced technical analysis of AsyncRAT was last updated on 23 February 2024. The supplied content does not include additional technical or campaign details beyond that update marker.
The dfir.ch article says analysis of 1,000 AsyncRAT samples from ThreatFox found that the top three C2 ports in January 2024 were 6606, 7707, and 8808. This revealed continued widespread use of default or common builder settings in the wild.
The dfir.ch article states that Proofpoint reported QuasarRAT activity targeting NATO facilities in March 2023. This is the only explicitly dated operational use event described in the references.
Recorded Future's Adversary Infrastructure Report 2023 listed AsyncRAT, Quasar RAT, PlugX, ShadowPad, and DarkComet among the top malware families detected that year. The dfir.ch article cites this report as context for the prevalence of these commodity RATs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.