#asyncrat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #asyncrat, aggregated by home.social.
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
ShinyHunters Wage Broad Corporate Extortion Spree https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #ScatteredLAPSUS$Hunters #OracleEBusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #AustinLarsen #CVE202561882 #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
ShinyHunters Wage Broad Corporate Extortion Spree https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #ScatteredLAPSUS$Hunters #OracleEBusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #AustinLarsen #CVE202561882 #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
ShinyHunters Wage Broad Corporate Extortion Spree https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #ScatteredLAPSUS$Hunters #OracleEBusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #AustinLarsen #CVE202561882 #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
ShinyHunters Wage Broad Corporate Extortion Spree https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #ScatteredLAPSUS$Hunters #OracleEBusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #AustinLarsen #CVE202561882 #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
GitHub Abused to Spread Amadey, Lumma and Redline InfoStealers in Ukraine – Source:hackread.com https://ciso2ciso.com/github-abused-to-spread-amadey-lumma-and-redline-infostealers-in-ukraine-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #CyberAttacks #CyberAttack #SmokeLoader #Emmenhtal #AsyncRAT #Hackread #security #malware #Redline #Ukraine #Amadey #GitHub #Python #Lumma
-
GitHub Abused to Spread Amadey, Lumma and Redline InfoStealers in Ukraine https://hackread.com/github-abused-amadey-lumma-redline-infostealers-ukraine/ #Cybersecurity #CyberAttacks #CyberAttack #SmokeLoader #Emmenhtal #Security #AsyncRAT #Malware #Redline #Ukraine #Amadey #GitHub #Python #Lumma
-
The strange tale of ischhfd83: When cybercriminals eat their own – Source: news.sophos.com https://ciso2ciso.com/the-strange-tale-of-ischhfd83-when-cybercriminals-eat-their-own-source-news-sophos-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #cybercrimeforums #ThreatResearch #nakedsecurity #nakedsecurity #lummastealer #SophosXOps #AsyncRAT #backdoor #FEATURED #asyncrat #Backdoor #featured
-
Ghost in the Shell: Null-AMSI Bypasses Security to Deploy AsyncRAT https://thecyberexpress.com/asyncrat-attack/ #TheCyberExpressNews #remoteaccesstrojan #TheCyberExpress #FirewallDaily #ItachiUchiha #SasukeUchiha #DarkWebNews #CyberNews #Null-AMSI #AsyncRAT
-
Ghost in the Shell: Null-AMSI Bypasses Security to Deploy AsyncRAT https://thecyberexpress.com/asyncrat-attack/ #TheCyberExpressNews #remoteaccesstrojan #TheCyberExpress #FirewallDaily #ItachiUchiha #SasukeUchiha #DarkWebNews #CyberNews #Null-AMSI #AsyncRAT
-
Catch up on everything cyber with this week's edition of our SOC Goulash newsletter!:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-373
Images which were redacted or cropped on Google Pixel devices or using the Windows Snipping Tool can be reversed and sensitive data revealed. The bug, dubbed "Acropalypse", may have been fixed but any existing images - be they bank details, nudes, or confidential company information - remain up for grabs.
#Hacktivists launched a week-long, coordinated attack on Australian banks, hospitals, airports and more, in retaliation for an offensive submission by an Australian designer at the Melbourne Fashion Festival, of all things.
The takedown of #BreachForums was made official last week, with the subsequent disarray demonstrating that continued law enforcement action is succeeding in capitalising on the mistrust inherent to the cyber crime ecosystem.
A significant vulnerability in the #WooCommerce Payments plugin can let attackers takeover #WordPress sites, and a PoC #exploit has been released publicly for a vulnerability in #Veeam's backup software.
The #blueteam had a great week, with CISA releasing a tool that helps grab #Azure, #M365 and the #Defender suite telemetry to help run ad hoc investigations; #Splunk shared an awesome defensive guide to #ADCS attacks, and we've seen a bunch of great write-ups on #IcedID, #ASyncRAT, and more!
Catch all this and much more in this week's newsletter:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-373
#infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #acropalypse #OpAustralia #darkweb #CISA