Multiple malware campaigns delivered remote access trojans including NanoCore, NetWire, AsyncRAT, Quasar RAT, and PlugX through phishing lures and staged payloads behind legitimate-looking files. Cisco Talos reported a campaign that used malicious ZIP archives containing ISO images and heavily obfuscated JavaScript, batch, or VBScript loaders to fetch additional malware from Microsoft Azure and Amazon Web Services, while DuckDNS domains supported delivery and command-and-control. Fortinet separately documented travel-themed lures such as itinerary and booking files that pushed AsyncRAT and NetWire, often requiring victims to manually launch executables hidden inside ZIP or ISO containers; the use of ISO files helped bypass Mark-of-the-Web protections and reduced security scrutiny.
Fortinet also linked a separate espionage operation attributed to APT10 to DLL side-loading with the legitimate Java component jjs.exe, loading a malicious jli.dll, decrypting svchost.bin, and injecting shellcode into svchost.exe to deploy PlugX and a modified Quasar RAT. That activity used persistence via a service or a Run key named "Windows Updata", and relied on typosquatted infrastructure such as update.microsofts.org, update.kaspresksy.com, and cahe.microsofts.org. CISA has also tracked Quasar as an open-source remote administration tool, underscoring how both commodity and state-linked actors continue to rely on RAT malware, cloud-hosted staging, dynamic DNS, and deceptive attachment formats to gain and maintain access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Fortinet described a spearphishing attack against a military organization in Colombia using the subject line “Solicitud de Reserva para Mayo 2022” and an ISO attachment named RESERVA.ISO. When mounted and executed, the attachment delivered Quasar RAT communicating with opensea-user-reward[.]serveusers[.]com.
FortiGuard Labs observed another travel-themed AsyncRAT sample named Booking details.exe in early February 2022. The sample was part of a broader campaign using travel lures and connected to znets[.]ddns[.]net and dnets[.]ddns[.]net.
Cisco reported that Cisco Umbrella classified the malicious DuckDNS domains used in the NanoCore, NetWire, and AsyncRAT campaign as malicious on Oct. 26, 2021. The domains supported payload delivery and command-and-control.
Cisco Talos said NanoCore samples in the campaign used leaked version 1.2.2.0 and included a build date of Oct. 26, 2021. Talos also observed DuckDNS-based NanoCore command-and-control domains associated with the activity.
Cisco Talos discovered a phishing campaign around October 2021 delivering NanoCore, NetWire, and AsyncRAT through malicious ZIP attachments containing ISO images and script loaders. The campaign used Azure, AWS, and DuckDNS infrastructure to host payloads and command-and-control services.
Fortinet stated that the domain kingshakes1[.]linkpc[.]net appears to have been used by NetWire RAT since at least May 2021. In the travel-themed campaign, a JavaScript-delivered NetWire sample connected to this domain for command and control.
FortiGuard Labs reported suspected new activity by APT10 in April 2019 in Southeast Asia, with analyzed samples originating from the Philippines. The campaign used DLL side-loading via jjs.exe and malicious jli.dll to load and inject malware payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourceblog.talosintelligence.com
Open sourcefortinet.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.