AsyncRAT is an open-source remote access trojan written in .NET/C# and first publicly released in 2019. It is widely abused across cybercrime and espionage operations as a commodity post-compromise implant and is frequently delivered by loaders, crypters, phishing chains, and social-engineering frameworks rather than acting as the initial intrusion vector itself. Observed delivery ecosystems include phishing attachments, malicious Office documents, archive-based lures, shortcut and script chains, ClickFix-style fake verification prompts, DLL sideloading chains, steganographic droppers, and malware supply-chain loaders. It has also been observed as a payload delivered by services and frameworks such as Cruciferra and by compromised public-facing applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
AsyncRAT ... Exploitation of CVE-2022-30190 (Follina/MSDT “Dogwalk”) for arbitrary code execution ... Xworm ... Exploitation of the Follina vulnerability CVE-2022-30190 via malicious .docx files | AsyncRAT, a widely abused open-source RAT that recorded 275 hits... AsyncRAT is an open-source .NET/C# remote access trojan first published on GitHub...
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT. Additionally... the malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT
22 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The tool has delivered remote-access trojans and information stealers, including AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, Remcos, and XLoader.
a materially upgraded AsyncRAT build, internally codenamed JC-46, that introduces Windows Notification Facility (WNF) process injection, a custom Base28 payload encoding, a full Hidden VNC (HVNC) banking-fraud module with browser profile cloning, and a Chrome App-Bound Encryption (ABE) v20 bypass.
The group also deploys HiddenFace (aka NOOPDOOR), a modular backdoor observed only in MirrorFace operations, alongside a heavily customised version of AsyncRAT for additional control.
AsyncRAT est un cheval de Troie d’accès distant (RAT) open-source pour Windows, publié en janvier 2019 par le développeur NYAN-x-CAT sur GitHub. Il constitue la racine d’une famille de malwares ayant engendré environ 40 variants nommés à travers trois générations de forks successifs.
AsyncRAT in Action: UAC-0173’s Latest Advanced Antivirus Detection & Evasion Techniques
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers have used email lures, fake tax portals, PDF links, ZIP archives, and virtual hard disk files to deliver it... In one campaign, tax-themed messages impersonated the Income Tax Department... Other campaigns used U.S. Social Security Administration notices or guest complaint and bed-bug themes.
two small VBScript downloaders (System3.vbs, System5.vbs, roughly 790 bytes each) simply shell out to PowerShell to fetch two files from raw.githubusercontent.com and chain them together.
Malicious Excel spreadsheets (.xls) that drop a second .xls to trigger VBA macros
Hidden RDP (HRDP) Creates a hidden local admin account excluded from the login screen
AMSI bypass and process injection into aspnet_compiler.exe or explorer.exe
From there, an AES-256-ECB-encrypted PowerShell payload compiles inline C# via Add-Type and performs process hollowing into RegSvcs.exe
Client1.exe implements a working bypass for ABE v20 – escalating to SYSTEM via Winlogon token impersonation
before spawning the hollowing target, the script builds an extended STARTUPINFOEX attribute list with PROC_THREAD_ATTRIBUTE_PARENT_PROCESS... classic parent-process-ID spoofing
Four developments stood out during this collection window: a third distinct string-obfuscation scheme... a materially upgraded AsyncRAT build...
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
Observed campaigns have targeted financial services (34%), healthcare (25%), and government (10%), with notable attacks impersonating the Indian Income Tax Department and the US Social Security Administration.
AMSI bypass and process injection into aspnet_compiler.exe or explorer.exe
From there, an AES-256-ECB-encrypted PowerShell payload compiles inline C# via Add-Type and performs process hollowing into RegSvcs.exe
build a random %TEMP% folder, assemble an AES decryption stub in memory, execute it, and delete the evidence.
Client1.exe implements a working bypass for ABE v20 – escalating to SYSTEM via Winlogon token impersonation
before spawning the hollowing target, the script builds an extended STARTUPINFOEX attribute list with PROC_THREAD_ATTRIBUTE_PARENT_PROCESS... classic parent-process-ID spoofing
The reassembled stream is then fed into a genuinely custom decoder: a stateful cipher combining a running XOR accumulator, a small per-build rotation table, and an 8-bit rotate-right-by-3 operation
Category Capabilities Surveillance Keylogger; screenshot streaming; HVNC hidden desktop; webcam live stream
the RAT pauses the victim’s real browser process just long enough to copy its Chromium profile (cookies, Login Data, Local State, Web Data) into a clone directory
Category Capabilities Surveillance Keylogger; screenshot streaming; HVNC hidden desktop; webcam live stream
Category Capabilities Surveillance Keylogger; screenshot streaming; HVNC hidden desktop
Category Capabilities Surveillance Keylogger; screenshot streaming; HVNC hidden desktop; webcam live stream... audio capture
1,197 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan delivered as a payload via Cruciferra campaigns, including DLL sideloading and tax-themed delivery chains.
A malware payload delivered in campaigns using the Cruciferra crypter service.
An open-source .NET RAT used for remote access, persistence, and payload staging, commonly delivered through phishing attachments and cloud-hosted multi-stage scripts.
Mentioned only as a comparison for similar DLL sideloading tradecraft in another campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.