AsyncRAT is an open-source, C#/.NET-based remote-access trojan used to compromise Windows systems. It provides remote command execution, system-information collection, keylogging, screen capture, data theft, and command-and-control communications. Clients report host and user metadata, including operating-system details, privileges, and active-window information. AsyncRAT supports server-delivered plugins and commands for retrieving keystroke logs and clipboard contents, enabling surveillance and further post-compromise activity.
AsyncRAT includes configurable installation and persistence through scheduled tasks and registry autorun entries. Analyzed clients encrypt configuration values with AES and validate command-and-control server certificates. Anti-analysis checks can terminate execution when virtualization, debugging, or sandbox indicators are detected. Delivery chains commonly use obfuscated scripts, PowerShell, AutoIt, and in-memory .NET loading. Observed campaigns employ DLL sideloading, process hollowing, and injection into trusted Windows processes; some chains also patch AMSI and establish Startup-folder persistence. These techniques conceal the payload and reduce exposure to security inspection.
Distribution mechanisms include phishing and spear-phishing, judicial and tax-authority impersonation, invoice lures, fake browser updates, and cracked-software packages delivered by other loaders. AsyncRAT has also been deployed through compromised ConnectWise ScreenConnect infrastructure. Blind Eagle, also known as APT-C-36, has used it in Spanish-language campaigns, and TA582 deploys it to non-domain-joined systems in fake-update operations. Documented targeting includes individuals and organizations in Colombia, while cracked-software distribution reaches personal-computer users without a defined organizational or geographic focus. AsyncRAT is commodity tooling used by multiple operators rather than a family exclusive to one threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-1708 (CWE-22) — Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”). Base CVSS score of 8.4, still considered “High Priority”.
CVE-2024-1709 (CWE-288) — Authentication Bypass Using Alternate Path or Channel. Base CVSS score of 10, indicating “Critical”.
members of the VirusTotal community have linked it to exploitation of CVE-2022-30190, a Microsoft Support Diagnostic Tool (MSDT) vulnerability also known as Follina. Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT, and Qbot, which has previously delivered ransomware as a later-stage payload. | Threat actors have leveraged Follina to distribute malware, including the Rozena backdoor, AsyncRAT (remote access trojan), and Qbot, which has previously delivered ransomware as a later-stage payload.
Its most consistently used malware payloads included vjw0rm, njRAT, Revenge RAT, Loda, and AsyncRAT.
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive. | CRIL has recently identified and analyzed a campaign that is actively distributing various types of malware, including Apanyan Stealer, Murk-Stealer, and AsyncRAT.
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT. Additionally... the malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ AsyncRAT
38 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NullBulge ... reportedly uses publicly available tools ... like Async RAT and Xworm before delivering LockBit payloads built using the leaked Lockbit builder.
On February 20, a campaign was observed which varied slightly in its deployment, and which purpose was the deployment of AsyncRat.
On February 20, a campaign was observed which varied slightly in its deployment, and which purpose was the deployment of AsyncRat.
“Multiple samples of Asyncrat were dropped and executed, probably via the Quarian backdoor.”
Sandbox or VM environments scored by MintsLoader receive decoy executables, including AsyncRAT downloaded from temp[.]sh, rather than the real operational payload.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The TASK persistence option creates a Scheduled Task named SystemUpdate through schtasks.exe to execute at user logon.
“The final AsyncRAT payload provides attackers with remote access, including system information collection, command execution...”
The infection begins after a victim manually opens the batch file... It launches PowerShell with its window hidden.
PSE_REDIRECT_VBS decodes C2-provided VBScript, writes pse_<GUID>.vbs in %TEMP%, and executes it through wscript.exe.
The TASK persistence option creates a Scheduled Task named SystemUpdate through schtasks.exe to execute at user logon.
“It then starts the 32-bit Character Map program invisibly and uses Windows programming functions to allocate memory, copy in the payload, and create a new thread to run it.”
[PowerShell] decodes a payload using Base64 text, inserted junk characters, and XOR operations... an extensionless encrypted file... The loader decrypts its payload only in memory.
“A Blob can reassemble an archive in browser memory and hand it to the user as a download. It’s either the same smuggling technique long seen in HTML attachments, carried in something that presents as an image.”
“It then starts the 32-bit Character Map program invisibly and uses Windows programming functions to allocate memory, copy in the payload, and create a new thread to run it.”
SELFDESTRUCT deletes Run-key and scheduled-task persistence, creates a temporary batch file, deletes the malware executable, and deletes the batch file.
NETINFO enumerates active interfaces, IP addresses, MAC addresses, DNS servers, gateways, connection speed, and interface types.
NETSCAN identifies a local /24 subnet, sends ICMP pings to addresses 1–254, resolves hostnames through DNS, and reports reachable systems.
PROCLIST enumerates running processes and collects each PID, process name, memory use, and main-window title.
“The final AsyncRAT payload provides attackers with remote access, including system information collection.”
“The final AsyncRAT payload provides attackers with remote access, including ... Stealing...”
“The final AsyncRAT payload provides attackers with remote access, including ... Screen Capture...”
CLIPBOARD|GET reads current clipboard content using Clipboard.GetText() and sends it to C2; HVNC also supports clipboard read and write.
AUDIO starts microphone capture through Windows waveIn APIs, Base64-encodes collected audio, and sends AUDIODATA to C2.
The implant establishes an asynchronous TcpClient connection to hardcoded C2 address 181[.]235[.]1[.]253:2404 and exchanges command and data messages.
2,326 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commodity remote-access trojan delivered through SVG-based attachment chains in documented Latin American campaigns.
AsyncRAT is a remote-access trojan delivered through a multistage chain. An AutoIT-based initial loader and PowerShell execute a subsequent in-memory .NET payload. It enables system-information collection, arbitrary command execution, data theft, screen capture, and command-and-control communications.
Mentioned only as a malware-family comparison during final-payload identification; it is not the payload delivered in this campaign.
Mentioned only as a malware-family comparison during classification of the recovered .NET payload; the payload was ultimately identified as VenomRAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.