AsyncRAT is an open-source Windows remote access trojan first released in 2019 that has become both a widely used malware family and the basis for numerous forks and descendants, including DCRat. It is typically implemented as a .NET implant and is frequently deployed in commodity crimeware campaigns as well as in targeted intrusions. Security reporting has linked its use to a broad range of operators, including phishing and ClickFix-driven malware distributors, the UAC-0173 activity cluster, the BlindEagle ecosystem, and the China-aligned espionage group MirrorFace, which has used a heavily customized variant alongside other bespoke tooling.
On infected Windows systems, AsyncRAT provides full remote administration capabilities and commonly supports command execution, host reconnaissance, screenshot capture, keylogging, theft of browser and application data, collection of locally stored information, and exfiltration of stolen data to command-and-control infrastructure. Multiple analyses also show persistence mechanisms such as scheduled tasks or autorun entries, reflective loading, in-memory execution, process hollowing or injection, AMSI bypass or patching, security-tool enumeration, process termination, anti-debugging, anti-VM and anti-sandbox checks, and privilege-aware behavior. Some observed samples enable elevated privileges and use defense-evasion techniques to reduce detection before loading the main implant.
AsyncRAT is delivered through diverse intrusion chains. Document and archive lures, spearphishing attachments, malicious ISO images, HTA and PowerShell downloaders, DLL sideloading, AutoHotkey-based loaders, compromised websites, fake verification workflows, and ClickFix social-engineering pages have all been used to install it. It has also appeared in software supply-chain style distribution through trojanized code repositories and malicious packages. In several campaigns, AsyncRAT was staged alongside other malware families such as Quasar, Remcos, DarkGate, XWorm, NetSupport, SectopRAT, Vidar, and Gh0st RAT derivatives.
The malware primarily targets Microsoft Windows environments, including enterprise users, government and law-enforcement organizations, and general victims of financially motivated malware campaigns. Its long-lived open-source codebase, ease of customization, and broad criminal adoption have made it one of the most recognizable .NET RAT families in current threat activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT. Additionally... the malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT
25 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The delivery chain, HTA to PowerShell dropper fetching dddd.jpg from 83.136.211[.]85/files/ , ultimately installing an AsyncRAT instance with botnet name MaDOOOOOOOO_Work and C2 at 83.136.211[.]85:7077 , maps directly onto the dddd.ps1 found on the server.
The group also deploys HiddenFace (aka NOOPDOOR), a modular backdoor observed only in MirrorFace operations, alongside a heavily customised version of AsyncRAT for additional control.
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
AsyncRAT in Action: UAC-0173’s Latest Advanced Antivirus Detection & Evasion Techniques
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
By hosting implants in a portal used by both citizens and law enforcement personnel, the threat actor turned a tool built to make policing in Pakistan more accessible and accountable to the public into a malware delivery mechanism.
The China-nexus threat actor is also said to have compromised one of these web applications to deploy a custom implant masquerading as a portal update.
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com.
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result with execution-policy bypass.
a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
a VBScript dropper (mad_133517.vbs) employing three obfuscation layers, VBScript wrapping Base64-encoded PowerShell wrapping an AES-encrypted final payload
Two distinct variants of an implant called "cms_plugin.exe" have been uploaded to the site... samples display a message "Update Complete! Please refresh the page" upon execution, mimicking a CMS portal update. A .NET executable that masquerades as "360Safe.exe," a legitimate binary used by Qihoo 360 Total Security...
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result... Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The loader extracts it into a directory named to resemble a legitimate Microsoft Photos install and launches Microsoft.exe from that path with a hidden window.
The payload chain... communicates with Telegram or other public web services.
ANEL, HiddenFace and the customised AsyncRAT beacon to C2 over web protocols.
Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string 'LastW,' then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode.
1,082 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AsyncRAT6
A remote access trojan delivered as part of ClickFix payload rotation.
AsyncRAT appears as the payload loaded by a trojanized .NET executable hosted via the compromised Complaint Management System, providing remote access capability as part of the broader intrusion.
Remote access trojan-style payload detected in later stages of the loader chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.