Malware

AsyncRAT

AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victim’s computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques.

Indicators of Compromise 35

MITRE ATT&CK TTPs 46

T1006
Direct Volume Access
Defense Evasion
T1012
Query Registry
Discovery
T1014
Rootkit
Defense Evasion
T1027
Obfuscated Files or Information
Defense Evasion
T1027.013
Encrypted/Encoded File
Defense Evasion
T1036.005
Match Legitimate Name or Location
Defense Evasion
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1055.012
Process Hollowing
Defense Evasion
T1055.015
ListPlanting
Defense Evasion
T1057
Process Discovery
Discovery
T1059.001
PowerShell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1069.001
Local Groups
Discovery
T1070.004
File Deletion
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1085
T1085
T1090
Proxy
Command And Control
T1102.001
Dead Drop Resolver
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1112
Modify Registry
Defense Evasion
T1113
Screen Capture
Collection
T1133
External Remote Services
Persistence
T1140
Deobfuscate/Decode Files or Information
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1195.001
Compromise Software Dependencies and Development Tools
Initial Access
T1202
Indirect Command Execution
Defense Evasion
T1204.002
Malicious File
Execution
T1484.001
Group Policy Modification
Defense Evasion
T1490
Inhibit System Recovery
Impact
T1543.003
Windows Service
Persistence
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1548.002
Bypass User Account Control
Privilege Escalation
T1555.003
Credentials from Web Browsers
Credential Access
T1558.003
Kerberoasting
Credential Access
T1564.003
Hidden Window
Defense Evasion
T1566
Phishing
Initial Access
T1570
Lateral Tool Transfer
Lateral Movement
T1583
Acquire Infrastructure
Resource Development
T1584
Compromise Infrastructure
Resource Development
T1586
Compromise Accounts
Resource Development
T1608.001
Upload Malware
Resource Development
T1685
T1685

Source Articles

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actor Sable Squirrel has spent nearly $7 million acquiring expired domains to exploit their inherited reputation, traffic, and backlinks for illegal sports streaming, online gambling promotion, and malware distribution. The group operates a dual-purpose infrastructure where re-registered domains serve both as streaming platforms and command-and-control (C2) servers for malware such as Quasar RAT and HiddenTear ransomware. The operation targets users in Asia and Australia through social media and ad networks, using a traffic distribution system to redirect victims while evading detection. Additional scavenger actors like Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel are also abusing expired domains for ad fraud, tech support scams, and traffic resale.
hacker-news ·2w ago
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Kimsuky, a North Korean state-sponsored threat actor, is building an offline AI stack to enhance its phishing operations and automate malware development. The group has been observed deploying tools like Ollama, GPT4All, and Msty on its own infrastructure, with evidence of configured local document databases (localdocs_v3.db) indicating use of retrieval-augmented generation (RAG) for intelligence analysis. Additional tools such as LLaMaSharp, Microsoft Semantic Kernel, Whisper, and Cursor suggest efforts to integrate AI into custom malware development and speech-to-text processing. This activity supports the ongoing Operation GitPower, which abuses GitHub repositories as command-and-control channels and delivers AsyncRAT payloads.
hacker-news ·3w ago
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1mo ago
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
A malicious Go module, github.com/kaleidora/dnsub-scanning-tool, serves as a lure to deliver a multi-stage Windows malware chain involving hidden PowerShell execution and encrypted payload resolution via public dead drops. The campaign, tracked as Operation Muck and Load, leverages a network of 222 GitHub repositories across 190 accounts to create credibility and scale for malicious or deceptive software projects. These repositories use synthetic activity to appear recently maintained, facilitating social engineering and malware distribution. The final payload includes RATs such as AsyncRAT, Quasar, and Remcos, along with infostealers like Vidar, enabling credential theft, screen capture, and persistence.
socket-dev
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·1mo ago