Skip to content

AsyncRAT

AsyncRAT is a widely abused open-source .NET remote access trojan for Windows, first publicly released in 2019 and now common across commodity cybercrime operations.

Profile source: Mallory opens in a new tab

AsyncRAT

Family profile

AsyncRAT is a widely abused open-source .NET remote access trojan for Windows, first publicly released in 2019 and now common across commodity cybercrime operations. It is frequently deployed at the end of multi-stage infection chains and provides operators with persistent remote control, command execution, surveillance, and data theft capabilities. Reported functionality includes remote command execution, exfiltration of host information and other collected data, password recovery through plugin delivery, and keystroke logging via optional modules. AsyncRAT also supports extensibility through DLL-based plugins and commonly uses a mutex to prevent duplicate infections.

Observed Windows persistence mechanisms include Scheduled Tasks when installed with elevated privileges and Run-key style autoruns when running without elevation. Multiple investigations also associate AsyncRAT activity with defense evasion measures such as tampering with Microsoft Defender exclusions, disabling or weakening security controls, use of obfuscation in its .NET code, metadata cloning to resemble legitimate software, and code injection or process hollowing to reduce on-disk visibility. AsyncRAT has also appeared in campaigns involving DLL sideloading and staged PowerShell delivery.

Delivery has been observed through phishing attachments and links, malicious archives containing shortcut files, JavaScript or batch-script stages, fake software download sites, SEO-poisoned lure infrastructure, and cloud-hosted staging. It has also been delivered by other malware services and loaders, including crypter ecosystems such as Cruciferra and campaigns abusing legitimate remote administration tools such as ScreenConnect. Lures have included invoices, AI-themed documents, fake software installers, and tax-related themes.

AsyncRAT is used by a broad range of criminal operators rather than a single threat actor. It has been linked to activity involving groups such as RedFoxtrot and has appeared alongside other commodity malware families including Remcos, XWorm, Agent Tesla, Lumma Stealer, Formbook, and ValleyRAT. Targeting is opportunistic and broad, with observed victims spanning enterprise and public-sector environments including financial services, healthcare, government, education, manufacturing, nonprofits, and regional campaigns in Latin America. Its continued prevalence is driven by public source availability, low barrier to customization, and reliable utility for post-compromise remote access and surveillance.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
120 IP / 397 hostnames

Leading locations

  • US236
  • NL29
  • DE25
  • VN14
  • FR13
  • SG13
  • BE10
  • GB9
  • JP8
  • CN7
  • HK7
  • RU6

Leading providers

  • Cloudflare, Inc.177
  • Amazon.com, Inc.15
  • Google LLC12
  • Omegatech LTD10
  • Amarutu Technology Ltd8
  • BL Networks7

Infrastructure traits

  • Hosting 384
  • Anycast 203
  • Proxy 20
  • Vpn 8

Samples

Recent associated samples

Reported operators

Threat actors

23 named in public reporting
RedFoxtrot

RedFoxtrot utilise plusieurs méthodes et outils avec DcRat, notamment Cobalt Strike et AsyncRAT, pour l'infiltration et les activités de commande et de contrôle.

TA4922

The tool has delivered remote-access trojans and information stealers, including AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.

codemado

AsyncRAT avec botnet MaDOOOOOOOO_Work , C2 83.136.211.85:7077

APT-C-36

a materially upgraded AsyncRAT build, internally codenamed JC-46, that introduces Windows Notification Facility (WNF) process injection, a custom Base28 payload encoding, a full Hidden VNC (HVNC) banking-fraud module with browser profile cloning, and a Chrome App-Bound Encryption (ABE) v20 bypass.

MirrorFace

The group also deploys HiddenFace (aka NOOPDOOR), a modular backdoor observed only in MirrorFace operations, alongside a heavily customised version of AsyncRAT for additional control.

qwqdanchun

AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.

UAC-0173

AsyncRAT in Action: UAC-0173’s Latest Advanced Antivirus Detection & Evasion Techniques

alexeikun

AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.

NYAN-x-CAT

AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.

TA2541

Typically, TA2541 will use Visual Basic Script (VBS) files to establish persistence with one of their favorite payloads, AsyncRAT.

Nullbulge

The group uses tools like Async RAT and Xworm before delivering LockBit payloads built using the leaked Lockbit Black builder.

SideCopy

The use of XenoRAT specifically strengthens this attribution, as Seqrite Labs confirmed in December 2024 that SideCopy had formally adopted customised XenoRAT variants as part of their updated toolset, following a similar pattern of open-source RAT adoption seen previously with AsyncRAT.

Kimsuky

Post lazarusholic lazarusholic.bsky.social did:plc:iqisolaecmif2zmpfbmsq2te "APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析" published by Qihoo360. #APT-C-55, #AsyncRAT, #Github, #LNK, #DPRK, #CTI

KongTuke

The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.

TA583

Prior to mid-2024, this actor mostly deployed AsyncRAT and used ScreenConnect as a first stage payload less frequently. However, since mid-2024, the actor has primarily used ScreenConnect as an initial access payload. Proofpoint has also observed ScreenConnect on several occasions download and install AsyncRAT following an infection.

MuddyWater

The intrusions involved the use of a widely available .NET-based remote access Trojan AsyncRAT. ... AsyncRAT gives attackers a range of capabilities, including keystroke logging, screen capture and remote command execution.

TA558

“The execution of the BAT file led to a PowerShell helper script that downloaded a follow-on payload, AsyncRAT,” researchers wrote.

TA571

TA571 regularly uses 404 TDS in campaigns to deliver malware, including AsyncRAT, NetSupport, and DarkGate.

Andariel

...open-source and dual-use tools as used and/or customized by the actors: ... AsyncRAT ...

Red Akodon

...glib-2.0.dll: Biblioteca maliciosa encargada de inyectar AsyncRAT en el proceso MSBuild.exe...

Stonefly/Clasiopa

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT

PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

ShadowSyndicate

First released in 2019, AsyncRAT enables long-term unauthorized access and post-compromise control, making it a reliable tool for credential theft, lateral movement staging, and follow-on payload delivery.

Exploited software

Vulnerabilities linked to AsyncRAT

5 CVEs

MITRE ATT&CK

AsyncRAT in ATT&CK

115 distinct techniques

Techniques

115 techniques
T1562 Impair Defenses T1053.005 Scheduled Task T1059.001 PowerShell T1562.001 Disable or Modify Tools T1027 Obfuscated Files or Information T1071 Application Layer Protocol T1547.001 Registry Run Keys / Startup Folder T1555 Credentials from Password Stores T1036 Masquerading T1056.001 Keylogging T1027.013 Encrypted/Encoded File T1204.002 Malicious File T1059.003 Windows Command Shell T1219 Remote Access Tools T1055.012 Process Hollowing T1036.006 Space after Filename T1036.004 Masquerade Task or Service T1588.001 Malware T1113 Screen Capture T1059 Command and Scripting Interpreter T1071.001 Web Protocols T1053 Scheduled Task/Job T1125 Video Capture T1105 Ingress Tool Transfer T1102.002 Bidirectional Communication T1189 Drive-by Compromise T1566 Phishing T1132 Data Encoding T1055 Process Injection T1566.001 Spearphishing Attachment T1568 Dynamic Resolution T1566.002 Spearphishing Link T1059.007 JavaScript T1553.002 Code Signing T1560 Archive Collected Data T1059.005 Visual Basic T1204 User Execution T1203 Exploitation for Client Execution T1027.003 Steganography T1123 Audio Capture T1134.004 Parent PID Spoofing T1140 Deobfuscate/Decode Files or Information T1082 System Information Discovery T1134.001 Token Impersonation/Theft T1218 System Binary Proxy Execution T1547 Boot or Logon Autostart Execution T1070.004 File Deletion T1136.001 Local Account T1518 Software Discovery T1539 Steal Web Session Cookie T1564.003 Hidden Window T1555.003 Credentials from Web Browsers T1115 Clipboard Data T1021.001 Remote Desktop Protocol T1548 Abuse Elevation Control Mechanism T1046 Network Service Discovery T1021.005 VNC T1505 Server Software Component T1656 Impersonation T1190 Exploit Public-Facing Application T1620 Reflective Code Loading T1195 Supply Chain Compromise T1102.001 Dead Drop Resolver T1564 Hide Artifacts T1005 Data from Local System T1543.003 Windows Service T1505.003 Web Shell T1584 Compromise Infrastructure T1574.001 DLL T1548.002 Bypass User Account Control T1057 Process Discovery T1587.001 Malware T1583.003 Virtual Private Server T1497 Virtualization/Sandbox Evasion T1497.001 System Checks T1041 Exfiltration Over C2 Channel T1069.001 Local Groups T1106 Native API T1547.009 Shortcut Modification T1033 System Owner/User Discovery T1036.005 Match Legitimate Resource Name or Location T1095 Non-Application Layer Protocol T1134.002 Create Process with Token T1134 Access Token Manipulation T1564.001 Hidden Files and Directories T1027.002 Software Packing T1055.002 Portable Executable Injection T1622 Debugger Evasion T1027.007 Dynamic API Resolution T1068 Exploitation for Privilege Escalation T1027.009 Embedded Payloads T1573.001 Symmetric Cryptography T1608.006 SEO Poisoning T1055.004 Asynchronous Procedure Call T1218.011 Rundll32 T1102 Web Service T1218.005 Mshta T1047 Windows Management Instrumentation T1112 Modify Registry T1069 Permission Groups Discovery T1486 Data Encrypted for Impact T1036.002 Right-to-Left Override T1583.006 Web Services T1564.006 Run Virtual Instance T1568.002 Domain Generation Algorithms T1048 Exfiltration Over Alternative Protocol T1127.001 MSBuild T1059.006 Python T1573 Encrypted Channel T1218.010 Regsvr32 T1571 Non-Standard Port T1204.001 Malicious Link T1090.003 Multi-hop Proxy T1102.003 One-Way Communication T1083 File and Directory Discovery

Reporting

Research mentioning AsyncRAT

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 21
Cyber Security News

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.

Jul 21
Scworld

Sophisticated crypter service Cruciferra evades detection with advanced techniques | brief | SC Media

Jul 21
Gurucul Threat Research

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Community Portal | Gurucul

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.

Jul 17
Levelblue Spiderlabs

Still Circling: Blind Eagle's Toolkit Keeps Evolving

Blind Eagle, also tracked as TAG-144, APT-C-36, and linked by some researchers to Red Akodon, continued targeting organizations across South America with a sustained emphasis on Colombian government entities at the local, municipal, and federal levels. Researchers described multi-stage intrusion chains using spearphishing, including compromised Colombian government email accounts, to deliver commodity and cracked remote access trojans through exposed Apache staging servers, dynamic DNS infrastructure, and legitimate internet services used for payload staging. The group has remained active since at least 2018, blending credential theft, financial crime, and surveillance-oriented collection against public-sector targets. Recent activity shows the actor refining rather than replacing its established toolkit. Investigators observed VBScript-to-PowerShell delivery chains, steganography to conceal payloads in image files, a new JavaScript stage with custom AES-based string obfuscation, an AutoIt3 RunPE loader fetched from raw.githubusercontent.com, and repeated use of the "Photo Studio" persistence disguise. The most significant upgrade was a new AsyncRAT variant, JC-46, which adds WNF-based process injection, custom Base28 encoding, HVNC support for banking fraud, browser profile cloning, and a bypass for Chrome App-Bound Encryption v20, while the group continued reusing VPN-linked command-and-control infrastructure and familiar dynamic DNS patterns.

Jul 16
Proofpoint

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.