Security researchers reported an AsyncRAT malware campaign that used phishing emails and HTML smuggling to deliver malicious ISO images while bypassing traditional network inspection. The lures arrived as HTML attachments disguised as receipts or order confirmations, with embedded JavaScript reconstructing a Base64-encoded ISO directly in the victim’s browser instead of downloading it from a remote server. Researchers said the activity was active from at least September 2021 and in some cases also used drive-by delivery, with the technique helping the attackers evade sandboxes, proxies, firewalls, and many antimalware engines for months.
When victims opened the mounted ISO on Windows, it exposed a .bat or .vbs file that launched PowerShell, fetched or unpacked additional stages, established persistence, and executed .NET components in memory before deploying AsyncRAT and in some cases NJRAT. The campaign used multiple defense-evasion measures, including antivirus checks, Windows Defender exclusions, UAC bypass, disabling Action Center notifications, reflective DLL loading, and process injection into legitimate binaries such as aspnet_compiler.exe and MSBuild.exe; researchers also linked earlier variants to crypter-as-a-service tools including HCrypt and Alosh and warned of follow-on risks including credential theft and data exfiltration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Morphisec described an active phishing campaign using HTML attachments named like receipts to generate ISO payloads locally in the browser, avoiding remote ISO downloads and helping evade network inspection. The infection chain mounted the ISO, launched a BAT or VBS file, used PowerShell and an in-memory .NET module, and commonly hid the final AsyncRAT payload inside aspnet_compiler.exe.
Morphisec said a phishing campaign delivering AsyncRAT through HTML attachments disguised as receipts could be traced back to September 12, 2021. The campaign used embedded JavaScript to generate a malicious ISO locally in the victim's browser from a Base64 string.
Menlo Security reported a campaign it named ISOMorph that used HTML smuggling via email attachments and drive-by downloads to locally generate malicious ISO files in the browser and ultimately install AsyncRAT/NJRAT on Windows systems. The report also described persistence, reflective DLL loading, and injection into MSBuild.exe, with payloads hosted on Discord.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourcethehackernews.com
Open sourcemenlosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.