home.social

#asyncrat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #asyncrat, aggregated by home.social.

  1. Still Circling: Inside the Operator Behind the GitHub Loader

    An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.

    Pulse ID: 6a9226b8695b02a09a6160ef
    Pulse Link: otx.alienvault.com/pulse/6a922
    Pulse Author: AlienVault
    Created: 2026-08-29 00:24:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault

  2. Illegal Streaming Fronts a $7M Dropcatch Domain Operation

    Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

    Pulse ID: 6a7deb5d13e63e6a0ff237b2
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault