Tag: AsyncRAT

DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files
News

DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files

Threat researchers have revealed information about a new, covert malware campaign called DEAD#VAX that uses a combination of "disciplined tradecraft and clever abuse of legitimate system features" to get past conventional detection methods and install the AsyncRAT remote access trojan (RAT). According to a report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the attack uses IPFS-hosted VHD files, extreme script obfuscation, runtime decryption, and in-memory shellcode injection into trusted Windows processes, never dropping a decrypted binary to disk. Through keylogging, screen and webcam capture, clipboard monitoring, file system access, remote command execution, and persistence between reboots, the open-source malware Asyn...
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto
News

AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

Researchers in cybersecurity have revealed the specifics of a new campaign that uses the legitimate Remote Monitoring and Management (RMM) program ConnectWise ScreenConnect to deliver a fleshless loader that drops the AsyncRAT remote access trojan (RAT) to steal private information from compromised hosts. After gaining remote access via ScreenConnect, the attacker ran a layered PowerShell loader and VBScript script that retrieved and ran obfuscated components from external URLs. According to a source provided to The Hacker News, LevelBlue stated. Among these were encoded.NET assemblies that eventually unpacked into AsyncRAT while retaining persistence through a fictitious scheduled activity called "Skype Updater. According to the cybersecurity company's documentation of the infectio...
AsyncRAT’s Open-Source Code Sparks Surge in Dangerous Malware Variants Across the Globe
News

AsyncRAT’s Open-Source Code Sparks Surge in Dangerous Malware Variants Across the Globe

Researchers studying cybersecurity have traced the development of AsyncRAT, a popular remote access trojan that was initially made available on GitHub in January 2019 and has since been the basis for a number of different variations. ESET researcher Nikola Knežević stated in a report published with The Hacker News that AsyncRAT has solidified its position as a fundamental component of contemporary malware and as a ubiquitous threat that has developed into a vast network of forks and variants. Even though AsyncRAT's capabilities aren't very remarkable on their own, its open-source nature has really increased its influence. Numerous forks have proliferated due to its plug-in-based architecture and simplicity of modification, further pushing the bounds. Although AsyncRAT's developme...
Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets
News

Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets

A new malware operation is using a flaw in Discord's invitation mechanism to spread the AsyncRAT remote access trojan and the information-stealing program Skuld. Through vanity link registration, the attackers were able to take control of the links and covertly reroute users from reliable sources to malicious servers, according to a technical report from Check Point. To covertly distribute AsyncRAT and a customized Skuld Stealer that targets cryptocurrency wallets, the attackers used a combination of time-based evasions, multi-stage loaders, and the ClickFix phishing tactic. The problem with Discord's invite method is that it gives hackers the ability to steal invite links that have expired or been removed and covertly reroute unwary users to malicious servers that they control. ...