#asyncrat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #asyncrat, aggregated by home.social.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
📢 Kimsuky / Operation GitPower : LLM locaux, AsyncRAT chiffré et C2 GitHub
Ce rapport de threat intelligence documente Operation GitPower, une campagne attribuée au groupe nord-coréen Kimsuky (opérant sous le Reconnaissance General Bureau). Il s'inscrit dans la continuité de la campagne FlowerPower (2023) et d'une campagne de 2024 déguisée en éditorial…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-10-kimsuky-operation-gitpower-llm-locaux-asyncrat-chiffre-et-c2-github/
🌐 source : https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
🟡 vérification factuelle moyenne
#AsyncRAT #Kimsuky #Cyberveille -
📢 Écosystème malware Telegram : 9 898 bots C2 cartographiés via VirusTotal et Bot API
📝 📰 **Source** : Ransom-ISAC (ransom-isac.org), publié le 27 juillet 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-07-29-ecosysteme-malware-telegram-9-898-bots-c2-cartographies-via-virustotal-et-bot-api/
🌐 source : https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
#AgentTesla #AsyncRAT #Cyberveille -
📢 Trois campagnes AiTM exposées via un serveur mal configuré : codemado, mail-argenta, saroula01
📝 ## 🔍 ContexteLe 13 juillet 2026, l'équipe CTI de Lexfo publie une analyse approfondie issue de la découverte, fin avril 2026, d'un *...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-17-trois-campagnes-aitm-exposees-via-un-serveur-mal-configure-codemado-mail-argenta-saroula01/
🌐 source : https://blog.lexfo.fr/opendir-to-phishing-operator.html
#AiTM #AsyncRAT #Cyberveille -
📢 ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus
📝 ## 🔍 ContexteArticle de recherche publié le 16 juillet 2026 par Toni Dujmović, analyste chez ReversingLabs, basé sur une investigation réelle...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-18-clickfix-une-methodologie-d-attaque-industrialisee-invisible-aux-edr-et-antivirus/
🌐 source : https://www.reversinglabs.com/blog/clickfix-attacks-your-trust
#AsyncRAT #ClickFix #Cyberveille -
A malicious Go module exposed a GitHub lure network of 222 repositories, dubbed Operation Muck and Load, staging RATs and infostealers.
#GoModule #SupplyChain #GitHub #Malware #InfoStealer #AsyncRAT #DevSecOps #InfoSec
-
A malicious Go module exposed a GitHub lure network of 222 repositories, dubbed Operation Muck and Load, staging RATs and infostealers.
#GoModule #SupplyChain #GitHub #Malware #InfoStealer #AsyncRAT #DevSecOps #InfoSec
-
A massive ScreenConnect AsyncRAT campaign uses SEO poisoning and spoofed websites to drop malicious installer archives via remote monitoring tools.
-
A massive ScreenConnect AsyncRAT campaign uses SEO poisoning and spoofed websites to drop malicious installer archives via remote monitoring tools.
-
📢 Millenium RAT v4 : migration vers C++, MaaS à 50$/mois, 62 000 endpoints compromis
📝 ## 🔍 ContextePublié le 25 juin 2026 par Group-IB (blog officiel), cet article présente une analyse technique approfondie du **Millenium RAT version 4.***, un cheval d...
📖 cyberveille : https://cyberveille.ch/posts/2026-06-29-millenium-rat-v4-migration-vers-c-maas-a-50-mois-62-000-endpoints-compromis/
🌐 source : https://www.group-ib.com/blog/millenium-rat-maas/
#AsyncRAT #IOC #Cyberveille -
Fake AI Guides Spread AsyncRAT Malware: How Cybercriminals Hijack Dev Tools - https://www.redpacketsecurity.com/cybercriminals-use-fake-ai-guides-and-dev-tools-to-spread-asyncrat-malware/
-
Fake AI Guides Spread AsyncRAT Malware: How Cybercriminals Hijack Dev Tools - https://www.redpacketsecurity.com/cybercriminals-use-fake-ai-guides-and-dev-tools-to-spread-asyncrat-malware/
-
Fake AI Guides Spread AsyncRAT Malware: How Cybercriminals Hijack Dev Tools - https://www.redpacketsecurity.com/cybercriminals-use-fake-ai-guides-and-dev-tools-to-spread-asyncrat-malware/
-
Fake AI Guides Spread AsyncRAT Malware: How Cybercriminals Hijack Dev Tools - https://www.redpacketsecurity.com/cybercriminals-use-fake-ai-guides-and-dev-tools-to-spread-asyncrat-malware/
-
Fake AI Guides Spread AsyncRAT Malware: How Cybercriminals Hijack Dev Tools - https://www.redpacketsecurity.com/cybercriminals-use-fake-ai-guides-and-dev-tools-to-spread-asyncrat-malware/
-
New findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.
Read: https://hackread.com/hackers-fake-claude-code-guide-ai-pdfs-asyncrat/
-
New findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.
Read: https://hackread.com/hackers-fake-claude-code-guide-ai-pdfs-asyncrat/
-
New findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.
Read: https://hackread.com/hackers-fake-claude-code-guide-ai-pdfs-asyncrat/
-
New findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.
Read: https://hackread.com/hackers-fake-claude-code-guide-ai-pdfs-asyncrat/
-
New findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.
Read: https://hackread.com/hackers-fake-claude-code-guide-ai-pdfs-asyncrat/
-
@malware_traffic Thank you for sharing Brad!
The TLS traffic to173.232.146.62:25658looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD590389d2988cce2fe508087618dd2f519fromfnjnbehjangelkd[.]top? -
@malware_traffic Thank you for sharing Brad!
The TLS traffic to173.232.146.62:25658looks like #AsyncRAT or possibly #PureRAT. Can you confirm if it was generated by the powershell script with MD590389d2988cce2fe508087618dd2f519fromfnjnbehjangelkd[.]top? -
A domain registration is more like a lease rather than a deed. You get the exclusive right to use a domain name for a fixed term, but if you miss renewal, someone else can swoop in. What's scary is that with dropcatch services, cybercriminals can automate monitoring of pending‑delete domains and fire off registrations the split‑second a name is deleted by the registry and becomes available again. Think hawks circling for high‑value prey. 🦅
That's what happened to fita[.]org, a popular website owned by the Federation of International Trade Associations (FITA) and referenced by many government bodies including the International Trade Administration (trade.gov). The domain now sits behind Cloudflare and functions as a command-and-control (C2) for the AsyncRAT malware. The actor controlling it also stood up these C2 endpoints:
90phutif[.]cc,90phutis[.]cc,90phutiv[.]cc,90phuttn[.]cc,xoilaclinkf[.]cc,xoilactivi[.]uk,xoilactivik[.]cc,xoilactivil[.]cc,xoilactivim[.]cc,xoilactivin[.]cc,xoilactivio[.]cc,xoilactivip[.]cc,xoilactiviq[.]cc,xoilactivir[.]cc,xoilactivis[.]cc,xoilactivit[.]cc,xoilactiviu[.]cc,xoilactiviv[.]cc,xoilactiviw[.]cc,xoilactivix[.]cc,xoilactiviy[.]cc,xoilactiviz[.]cc,xoilacvnnc[.]tv,xoilacvnnf[.]tv,xoilacvzb[.]cc,xoilacvzc[.]cc,xoilacvze[.]cc,xoilacvzi[.]cc,xoilacvzk[.]cc,xoilacvzn[.]cc,xoilacvzp[.]cc,xoilacvzq[.]cc,xoilacvzz[.]cc,xoilacyys[.]cc,xoilaczc[.]mobi,xoilaczzbb[.]cc,xoilaczzczz[.]tv,xoilaczzdd[.]cc,xoilaczzdzz[.]tv,xoilaczziz[.]tv,xoilaczzszz[.]tv,xoilaczzvzz[.]tv
So make sure to set auto pay for any valuable domains you possess 💳 otherwise you could risk losing them. Proactive IT governance is also part of security.
#InfobloxThreatIntel #dns #async #threatintel #threatintelligence #infosec #cybersecurity #cybercrime #infoblox #rat #asyncrat #malware #dropcatch #domain #cloudflare #remoteaccesstrojan #infostealer #c2
-
A domain registration is more like a lease rather than a deed. You get the exclusive right to use a domain name for a fixed term, but if you miss renewal, someone else can swoop in. What's scary is that with dropcatch services, cybercriminals can automate monitoring of pending‑delete domains and fire off registrations the split‑second a name is deleted by the registry and becomes available again. Think hawks circling for high‑value prey. 🦅
That's what happened to fita[.]org, a popular website owned by the Federation of International Trade Associations (FITA) and referenced by many government bodies including the International Trade Administration (trade.gov). The domain now sits behind Cloudflare and functions as a command-and-control (C2) for the AsyncRAT malware. The actor controlling it also stood up these C2 endpoints:
90phutif[.]cc,90phutis[.]cc,90phutiv[.]cc,90phuttn[.]cc,xoilaclinkf[.]cc,xoilactivi[.]uk,xoilactivik[.]cc,xoilactivil[.]cc,xoilactivim[.]cc,xoilactivin[.]cc,xoilactivio[.]cc,xoilactivip[.]cc,xoilactiviq[.]cc,xoilactivir[.]cc,xoilactivis[.]cc,xoilactivit[.]cc,xoilactiviu[.]cc,xoilactiviv[.]cc,xoilactiviw[.]cc,xoilactivix[.]cc,xoilactiviy[.]cc,xoilactiviz[.]cc,xoilacvnnc[.]tv,xoilacvnnf[.]tv,xoilacvzb[.]cc,xoilacvzc[.]cc,xoilacvze[.]cc,xoilacvzi[.]cc,xoilacvzk[.]cc,xoilacvzn[.]cc,xoilacvzp[.]cc,xoilacvzq[.]cc,xoilacvzz[.]cc,xoilacyys[.]cc,xoilaczc[.]mobi,xoilaczzbb[.]cc,xoilaczzczz[.]tv,xoilaczzdd[.]cc,xoilaczzdzz[.]tv,xoilaczziz[.]tv,xoilaczzszz[.]tv,xoilaczzvzz[.]tv
So make sure to set auto pay for any valuable domains you possess 💳 otherwise you could risk losing them. Proactive IT governance is also part of security.
#InfobloxThreatIntel #dns #async #threatintel #threatintelligence #infosec #cybersecurity #cybercrime #infoblox #rat #asyncrat #malware #dropcatch #domain #cloudflare #remoteaccesstrojan #infostealer #c2
-
I finished compiling the information for #Kongtuke #ClickFix activity using the finger command on 2025-12-11, and it's now live at www.malware-traffic-analysis.net/2025/12/11/index2.html
I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.
I had to run the ClickFix command on a physical host because the C2 server didn't like me when I initially tried it on a VM.
Post-infection traffic looks like the same type of #AsyncRAT I've seen before, and some Tor traffic from whatever the follow-up malware is.
It's a 221 MB zip archive containing the #pcap for the full infection, and it's about the same size as the zip archive containing forensic artifacts from the infected host.
-
I finished compiling the information for #Kongtuke #ClickFix activity using the finger command on 2025-12-11, and it's now live at www.malware-traffic-analysis.net/2025/12/11/index2.html
I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.
I had to run the ClickFix command on a physical host because the C2 server didn't like me when I initially tried it on a VM.
Post-infection traffic looks like the same type of #AsyncRAT I've seen before, and some Tor traffic from whatever the follow-up malware is.
It's a 221 MB zip archive containing the #pcap for the full infection, and it's about the same size as the zip archive containing forensic artifacts from the infected host.
-
-
ShinyHunters Wage Broad Corporate Extortion Spree https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #ScatteredLAPSUS$Hunters #OracleEBusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #AustinLarsen #CVE202561882 #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
ShinyHunters Wage Broad Corporate Extortion Spree https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #ScatteredLAPSUS$Hunters #OracleEBusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #AustinLarsen #CVE202561882 #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
ShinyHunters Wage Broad Corporate Extortion Spree
https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/
#ScatteredLAPSUS$Hunters #OracleE-BusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #CVE-2025-61882 #AustinLarsen #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
ShinyHunters Wage Broad Corporate Extortion Spree
https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/
#ScatteredLAPSUS$Hunters #OracleE-BusinessSuite #Ne'er-Do-WellNews #CharlesCarmichael #CrimsonCollective #ALittleSunshine #LatestWarnings #TheComingStorm #CVE-2025-61882 #AustinLarsen #ShinyHunters #Ransomware #Salesforce #Salesloft #ASYNCRAT #UNC6040 #UNC6395
-
China-Linked AI Pentest Tool ‘Villager’ Raises Concern After 10K Downloads https://hackread.com/china-ai-pentest-tool-villager-10k-downloads/ #Cybersecurity #CobaltStrike #Cyberspike #Security #AsyncRAT #Straiker #Villager #HSCSEC #China #PyPI #CTF
-
China-Linked AI Pentest Tool ‘Villager’ Raises Concern After 10K Downloads https://hackread.com/china-ai-pentest-tool-villager-10k-downloads/ #Cybersecurity #CobaltStrike #Cyberspike #Security #AsyncRAT #Straiker #Villager #HSCSEC #China #PyPI #CTF
-
This widely used Remote Monitoring tool is being used to deploy AsyncRAT to steal passwords | TechRadar https://www.techradar.com/pro/security/this-widely-used-remote-monitoring-tool-is-being-used-to-deploy-asyncrat-to-steal-passwords
#cybersecurity #ScreenConnect #AsyncRAT #fileless #malware -
Attackers abuse ConnectWise ScreenConnect to drop AsyncRAT – Source: securityaffairs.com https://ciso2ciso.com/attackers-abuse-connectwise-screenconnect-to-drop-asyncrat-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #filelessmalware #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #AsyncRAT #Security #hacking #Malware #RAT
-
Attackers abuse ConnectWise ScreenConnect to drop AsyncRAT – Source: securityaffairs.com https://ciso2ciso.com/attackers-abuse-connectwise-screenconnect-to-drop-asyncrat-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #filelessmalware #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #AsyncRAT #Security #hacking #Malware #RAT
-
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto – Source:thehackernews.com https://ciso2ciso.com/asyncrat-exploits-connectwise-screenconnect-to-steal-credentials-and-crypto-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #AsyncRAT
-
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto – Source:thehackernews.com https://ciso2ciso.com/asyncrat-exploits-connectwise-screenconnect-to-steal-credentials-and-crypto-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #AsyncRAT
-
New Fileless Malware Attack Uses AsyncRAT for Credential Theft https://hackread.com/fileless-malware-attack-asyncrat-credential-theft/ #Cybersecurity #ScreenConnect #CyberAttack #SentinelOne #Security #AsyncRAT #Fileless #Malware #TROJAN
-
New Fileless Malware Attack Uses AsyncRAT for Credential Theft https://hackread.com/fileless-malware-attack-asyncrat-credential-theft/ #Cybersecurity #ScreenConnect #CyberAttack #SentinelOne #Security #AsyncRAT #Fileless #Malware #TROJAN
-
New Fileless Malware Attack Uses AsyncRAT for Credential Theft – Source:hackread.com https://ciso2ciso.com/new-fileless-malware-attack-uses-asyncrat-for-credential-theft-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #ScreenConnect #CyberAttack #SentinelOne #AsyncRAT #Fileless #Hackread #security #malware #trojan
-
New Fileless Malware Attack Uses AsyncRAT for Credential Theft – Source:hackread.com https://ciso2ciso.com/new-fileless-malware-attack-uses-asyncrat-for-credential-theft-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #ScreenConnect #CyberAttack #SentinelOne #AsyncRAT #Fileless #Hackread #security #malware #trojan