Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 192 IP / 1066 hostnames
AsyncRAT is a Windows remote-access trojan used by multiple criminal and espionage operators for covert control of compromised endpoints.
Profile source: Mallory opens in a new tabAsyncRAT
AsyncRAT is a Windows remote-access trojan used by multiple criminal and espionage operators for covert control of compromised endpoints. It is commonly delivered through phishing and spear-phishing chains involving malicious archives, OneNote files, shortcut files, Internet Shortcut files, and trojanized installers. Observed delivery workflows use obfuscated PowerShell, Windows Script Host, WebDAV-hosted stages, and trusted or legitimate hosting services for payload staging and command-and-control. Some AsyncRAT deployments establish logon persistence through Startup-folder artifacts or scheduled tasks and use process injection to execute payloads within legitimate processes. AsyncRAT has appeared in campaigns associated with Kimsuky, TA558, and activity linked to Blind Eagle, as well as broad commodity-malware operations targeting government, financial, healthcare, industrial, energy, education, and other organizations globally.
C2 tracking
Derp observations, rolling seven-day window
Samples
b991bcf2d98bd447c5056e8682399a222ac3bdaf4f34dbca081ecd09b67b4b9f dd196dacf07be298a36a3e68cc577a90533bc5179291812a923949f6ba3fae23 7e9e1212464885777e000713ee20d492dea973ac24d5c614ed8a20dab057fe77 fda19deaa898c61e925c5e9866049dff8cdf1fe06caddcacec92c50b37c84e1e 32b44abb68fc72d85c2b258d59e0130ff29e60c59816d8f895602286c4c39f7f 8acdd22e51b40a29e555f79c515153b6619a331de0145d290cc79222e65fb529 aa463df16990937465e2c579923d19b35d7bff3c0f2e514efea6f1e942871ab0 c2aa45216a81da5e2296c3953f03da4432a56871422e9a88ab0816457cb5638c 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b Reported operators
“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Async RAT ...”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Investigators linked the campaign to AsyncRAT payloads stored in repositories and described GitHub as both a delivery location and a command-and-control channel.
Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
内存加载PE,经过分析,该PE为开源远控,AsyncRat。
According to the researcher’s observations, AsyncRAT, NetWire, WSH RAT, and Parallax appears to be the group’s top favorites being pushed most often in malicious messages.
Cisco Talos has observed a new malware campaign delivering commodity RATs, including njRAT and AsyncRAT.
As you can see, there was yet another .dll file, which turned out to be AsyncRAT. Associated C2 domains: Darwin090.gleeze[.]com randall010.camdvr[.]org
The Remote Access Trojan (RAT) used in this campaign (AsyncRAT) has many capabilities that are used to evade detection, log passwords, and exfiltrate data.
The Remote Access Trojan (RAT) used in this campaign (AsyncRAT) has many capabilities that are used to evade detection, log passwords, and exfiltrate data.
Among the well-known RATs are VenomRAT and AsyncRAT. These are open-source RATs and have been making headlines for their frequent use by different threat actors.
The Remote Access Trojan (RAT) used in this campaign (AsyncRAT) has many capabilities that are used to evade detection, log passwords, and exfiltrate data.
Among the well-known RATs are VenomRAT and AsyncRAT. These are open-source RATs and have been making headlines for their frequent use by different threat actors.
Among the well-known RATs are VenomRAT and AsyncRAT. These are open-source RATs and have been making headlines for their frequent use by different threat actors.
Cruciferra ... now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger.
RedFoxtrot utilise plusieurs méthodes et outils avec DcRat, notamment Cobalt Strike et AsyncRAT, pour l'infiltration et les activités de commande et de contrôle.
AsyncRAT avec botnet MaDOOOOOOOO_Work , C2 83.136.211.85:7077
The group also deploys HiddenFace (aka NOOPDOOR), a modular backdoor observed only in MirrorFace operations, alongside a heavily customised version of AsyncRAT for additional control.
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
AsyncRAT in Action: UAC-0173’s Latest Advanced Antivirus Detection & Evasion Techniques
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
The use of XenoRAT specifically strengthens this attribution, as Seqrite Labs confirmed in December 2024 that SideCopy had formally adopted customised XenoRAT variants as part of their updated toolset, following a similar pattern of open-source RAT adoption seen previously with AsyncRAT.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
Prior to mid-2024, this actor mostly deployed AsyncRAT and used ScreenConnect as a first stage payload less frequently. However, since mid-2024, the actor has primarily used ScreenConnect as an initial access payload. Proofpoint has also observed ScreenConnect on several occasions download and install AsyncRAT following an infection.
The intrusions involved the use of a widely available .NET-based remote access Trojan AsyncRAT. ... AsyncRAT gives attackers a range of capabilities, including keystroke logging, screen capture and remote command execution.
TA571 regularly uses 404 TDS in campaigns to deliver malware, including AsyncRAT, NetSupport, and DarkGate.
...open-source and dual-use tools as used and/or customized by the actors: ... AsyncRAT ...
...glib-2.0.dll: Biblioteca maliciosa encargada de inyectar AsyncRAT en el proceso MSBuild.exe...
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
First released in 2019, AsyncRAT enables long-term unauthorized access and post-compromise control, making it a reliable tool for credential theft, lateral movement staging, and follow-on payload delivery.
Exploited software
MITRE ATT&CK
Reporting
A FakeAgent campaign is using malicious search advertisements and counterfeit Claude Desktop download pages to deliver the SectopRAT remote-access trojan to Windows users. The trojanized installer reportedly executes PowerShell to add Microsoft Defender exclusions, then uses DLL sideloading via a signed Java Chromium Embedded Framework helper and creates a disguised elevated scheduled task for persistence. Associated indicators include Claude-themed download infrastructure, lookalike application components, and IP address 153.75.84.173. SectopRAT retrieves encrypted connection information through EtherHiding, using Ethereum blockchain data instead of a conventional command-and-control server. Organizations should isolate potentially affected endpoints, identify and remove unauthorized Defender exclusions and scheduled tasks, revoke credentials and active sessions used on exposed hosts, review identity activity, and reimage systems where execution is confirmed.
Researchers linked a North Korean Kimsuky intrusion cluster to spearphishing campaigns that deliver ZIP archives containing malicious .lnk files, which launch obfuscated PowerShell, open decoy PDF documents, and create persistence through scheduled tasks. The activity, tracked by Genians as Operation GitPower, also used public GitHub and GitLab repositories as command-and-control channels and malware staging infrastructure, including encrypted .NET AsyncRAT payloads disguised as image files. Fortinet separately reported DPRK-linked campaigns using the same combination of LNK-based infection chains and GitHub-backed C2, reinforcing the pattern across related operations. Investigators said the operators appear to be expanding beyond conventional malware delivery and are actively experimenting with AI-enabled tradecraft. Artifacts showed local LLM environments built with tools including Ollama, GPT4All, and Msty, along with RAG-style document handling, AI agent development libraries, and Whisper speech-to-text components, suggesting a research-and-integration phase focused on malware development, document analysis, and attack automation rather than training original models. Attribution was supported by overlaps with prior Kimsuky techniques, Korean-language artifacts, North Korean lexical patterns, Arirang manufacturer strings, and use of Astrill VPN.
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.