Skip to content

AsyncRAT

AsyncRAT is a Windows remote-access trojan used by multiple criminal and espionage operators for covert control of compromised endpoints.

Profile source: Mallory opens in a new tab

AsyncRAT

Family profile

AsyncRAT is a Windows remote-access trojan used by multiple criminal and espionage operators for covert control of compromised endpoints. It is commonly delivered through phishing and spear-phishing chains involving malicious archives, OneNote files, shortcut files, Internet Shortcut files, and trojanized installers. Observed delivery workflows use obfuscated PowerShell, Windows Script Host, WebDAV-hosted stages, and trusted or legitimate hosting services for payload staging and command-and-control. Some AsyncRAT deployments establish logon persistence through Startup-folder artifacts or scheduled tasks and use process injection to execute payloads within legitimate processes. AsyncRAT has appeared in campaigns associated with Kimsuky, TA558, and activity linked to Blind Eagle, as well as broad commodity-malware operations targeting government, financial, healthcare, industrial, energy, education, and other organizations globally.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
192 IP / 1066 hostnames

Leading locations

  • US583
  • DE38
  • NL33
  • CN32
  • SG29
  • HK26
  • VN15
  • GB11
  • BE10
  • RU8
  • FR7
  • KR7

Leading providers

  • Cloudflare, Inc.495
  • CNServer LLC19
  • Amazon.com, Inc.18
  • CTG Server Limited14
  • Google LLC11
  • HostPapa11

Infrastructure traits

  • Hosting 798
  • Anycast 520
  • Proxy 9

Samples

Recent associated samples

Reported operators

Threat actors

32 named in public reporting
APT-C-36

“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Async RAT ...”

Sable Squirrel

к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT

Kimsuky

Investigators linked the campaign to AsyncRAT payloads stored in repositories and described GitHub as both a delivery location and a command-and-control channel.

TA558

Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.

Confucius

内存加载PE,经过分析,该PE为开源远控,AsyncRat。

TA2541

According to the researcher’s observations, AsyncRAT, NetWire, WSH RAT, and Parallax appears to be the group’s top favorites being pushed most often in malicious messages.

Aggah

Cisco Talos has observed a new malware campaign delivering commodity RATs, including njRAT and AsyncRAT.

DDGroup

As you can see, there was yet another .dll file, which turned out to be AsyncRAT. Associated C2 domains: Darwin090.gleeze[.]com randall010.camdvr[.]org

Gorgon Group

The Remote Access Trojan (RAT) used in this campaign (AsyncRAT) has many capabilities that are used to evade detection, log passwords, and exfiltrate data.

Group5

The Remote Access Trojan (RAT) used in this campaign (AsyncRAT) has many capabilities that are used to evade detection, log passwords, and exfiltrate data.

Nullbulge

Among the well-known RATs are VenomRAT and AsyncRAT. These are open-source RATs and have been making headlines for their frequent use by different threat actors.

APT41

The Remote Access Trojan (RAT) used in this campaign (AsyncRAT) has many capabilities that are used to evade detection, log passwords, and exfiltrate data.

OPERA1ER

Among the well-known RATs are VenomRAT and AsyncRAT. These are open-source RATs and have been making headlines for their frequent use by different threat actors.

Coral Rider

Among the well-known RATs are VenomRAT and AsyncRAT. These are open-source RATs and have been making headlines for their frequent use by different threat actors.

TA4922

Cruciferra ... now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger.

RedFoxtrot

RedFoxtrot utilise plusieurs méthodes et outils avec DcRat, notamment Cobalt Strike et AsyncRAT, pour l'infiltration et les activités de commande et de contrôle.

codemado

AsyncRAT avec botnet MaDOOOOOOOO_Work , C2 83.136.211.85:7077

MirrorFace

The group also deploys HiddenFace (aka NOOPDOOR), a modular backdoor observed only in MirrorFace operations, alongside a heavily customised version of AsyncRAT for additional control.

qwqdanchun

AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.

UAC-0173

AsyncRAT in Action: UAC-0173’s Latest Advanced Antivirus Detection & Evasion Techniques

alexeikun

AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.

NYAN-x-CAT

AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.

SideCopy

The use of XenoRAT specifically strengthens this attribution, as Seqrite Labs confirmed in December 2024 that SideCopy had formally adopted customised XenoRAT variants as part of their updated toolset, following a similar pattern of open-source RAT adoption seen previously with AsyncRAT.

KongTuke

The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.

TA583

Prior to mid-2024, this actor mostly deployed AsyncRAT and used ScreenConnect as a first stage payload less frequently. However, since mid-2024, the actor has primarily used ScreenConnect as an initial access payload. Proofpoint has also observed ScreenConnect on several occasions download and install AsyncRAT following an infection.

MuddyWater

The intrusions involved the use of a widely available .NET-based remote access Trojan AsyncRAT. ... AsyncRAT gives attackers a range of capabilities, including keystroke logging, screen capture and remote command execution.

TA571

TA571 regularly uses 404 TDS in campaigns to deliver malware, including AsyncRAT, NetSupport, and DarkGate.

Andariel

...open-source and dual-use tools as used and/or customized by the actors: ... AsyncRAT ...

Red Akodon

...glib-2.0.dll: Biblioteca maliciosa encargada de inyectar AsyncRAT en el proceso MSBuild.exe...

Stonefly/Clasiopa

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT

PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

ShadowSyndicate

First released in 2019, AsyncRAT enables long-term unauthorized access and post-compromise control, making it a reliable tool for credential theft, lateral movement staging, and follow-on payload delivery.

Exploited software

Vulnerabilities linked to AsyncRAT

7 CVEs

MITRE ATT&CK

AsyncRAT in ATT&CK

93 distinct techniques

Techniques

93 techniques
T1059.005 Visual Basic T1218.004 InstallUtil T1071 Application Layer Protocol T1059.001 PowerShell T1568.003 DNS Calculation T1620 Reflective Code Loading T1055.004 Asynchronous Procedure Call T1204.002 Malicious File T1218.011 Rundll32 T1218.005 Mshta T1140 Deobfuscate/Decode Files or Information T1021.002 SMB/Windows Admin Shares T1027 Obfuscated Files or Information T1566.001 Spearphishing Attachment T1059.003 Windows Command Shell T1204 User Execution T1547.001 Registry Run Keys / Startup Folder T1036 Masquerading T1055 Process Injection T1608.006 SEO Poisoning T1203 Exploitation for Client Execution T1566.002 Spearphishing Link T1566 Phishing T1583 Acquire Infrastructure T1105 Ingress Tool Transfer T1560 Archive Collected Data T1129 Shared Modules T1189 Drive-by Compromise T1053.005 Scheduled Task T1102 Web Service T1584 Compromise Infrastructure T1219 Remote Access Tools T1059 Command and Scripting Interpreter T1564 Hide Artifacts T1564.003 Hidden Window T1056.001 Keylogging T1053.002 At T1518.001 Security Software Discovery T1127.001 MSBuild T1497 Virtualization/Sandbox Evasion T1001 Data Obfuscation T1027.013 Encrypted/Encoded File T1113 Screen Capture T1055.012 Process Hollowing T1221 Template Injection T1573 Encrypted Channel T1041 Exfiltration Over C2 Channel T1218.009 Regsvcs/Regasm T1082 System Information Discovery T1562 Impair Defenses T1070 Indicator Removal T1497.001 System Checks T1622 Debugger Evasion T1047 Windows Management Instrumentation T1568 Dynamic Resolution T1115 Clipboard Data T1027.002 Software Packing T1222.001 Windows File and Directory Permissions Modification T1218 System Binary Proxy Execution T1562.001 Disable or Modify Tools T1548.002 Bypass User Account Control T1112 Modify Registry T1518 Software Discovery T1049 System Network Connections Discovery T1548 Abuse Elevation Control Mechanism T1095 Non-Application Layer Protocol T1036.002 Right-to-Left Override T1059.007 JavaScript T1053 Scheduled Task/Job T1547 Boot or Logon Autostart Execution T1056 Input Capture T1070.004 File Deletion T1137 Office Application Startup T1555 Credentials from Password Stores T1059.006 Python T1005 Data from Local System T1027.006 HTML Smuggling T1204.001 Malicious Link T1571 Non-Standard Port T1036.005 Match Legitimate Resource Name or Location T1564.004 NTFS File Attributes T1583.001 Domains T1543 Create or Modify System Process T1195 Supply Chain Compromise T1505.003 Web Shell T1074 Data Staged T1071.001 Web Protocols T1204.004 Malicious Copy and Paste T1547.009 Shortcut Modification T1102.002 Bidirectional Communication T1057 Process Discovery T1016 System Network Configuration Discovery T1033 System Owner/User Discovery

Reporting

Research mentioning AsyncRAT

Aug 26
Cyber Security News

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

A FakeAgent campaign is using malicious search advertisements and counterfeit Claude Desktop download pages to deliver the SectopRAT remote-access trojan to Windows users. The trojanized installer reportedly executes PowerShell to add Microsoft Defender exclusions, then uses DLL sideloading via a signed Java Chromium Embedded Framework helper and creates a disguised elevated scheduled task for persistence. Associated indicators include Claude-themed download infrastructure, lookalike application components, and IP address 153.75.84.173. SectopRAT retrieves encrypted connection information through EtherHiding, using Ethereum blockchain data instead of a conventional command-and-control server. Organizations should isolate potentially affected endpoints, identify and remove unauthorized Defender exclusions and scheduled tasks, revoke credentials and active sessions used on exposed hosts, review identity activity, and reimage systems where execution is confirmed.

Aug 26
Cryptika

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware | Cryptika Cybersecurity

Aug 10
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Researchers linked a North Korean Kimsuky intrusion cluster to spearphishing campaigns that deliver ZIP archives containing malicious .lnk files, which launch obfuscated PowerShell, open decoy PDF documents, and create persistence through scheduled tasks. The activity, tracked by Genians as Operation GitPower, also used public GitHub and GitLab repositories as command-and-control channels and malware staging infrastructure, including encrypted .NET AsyncRAT payloads disguised as image files. Fortinet separately reported DPRK-linked campaigns using the same combination of LNK-based infection chains and GitHub-backed C2, reinforcing the pattern across related operations. Investigators said the operators appear to be expanding beyond conventional malware delivery and are actively experimenting with AI-enabled tradecraft. Artifacts showed local LLM environments built with tools including Ollama, GPT4All, and Msty, along with RAG-style document handling, AI agent development libraries, and Whisper speech-to-text components, suggesting a research-and-integration phase focused on malware development, document analysis, and attack automation rather than training original models. Attribution was supported by overlaps with prior Kimsuky techniques, Korean-language artifacts, North Korean lexical patterns, Arirang manufacturer strings, and use of Astrill VPN.

Aug 9
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Aug 9
Malware News

Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM - Malware News - Malware Analysis, News and Indicators

Aug 9
Genians

AI를 공격 체계에 접목하는 김수키, 미끼 문서 제작부터 로컬 LLM 구축까지

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.