AsyncRAT
MITRE ATT&CK: S1087 View on attack.mitre.org
Aliases: AsyncRAT
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 70073 (63441 malicious)
- Last IoC activity
- 2026-09-02 04:24:14
- Profile updated
- 2026-07-07 12:53:17
Context
AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.
Recent IoC activity
63,530 malicious indicators in Maltiverse are attributed to AsyncRAT (S1087). The 20 most recently updated:
Detection coverage
- 3 YARA rules
- 263 Sigma rules
Malware & tools used
- Debugger Evasion (attack-pattern)
- Windows Command Shell (attack-pattern)
- Native API (attack-pattern)
- System Time Discovery (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Local Storage Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Hidden Window (attack-pattern)
- System Checks (attack-pattern)
- Video Capture (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Malicious File (attack-pattern)
- Process Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Keylogging (attack-pattern)
- Scheduled Task (attack-pattern)
Used by threat actors
Detection rules
- SECUINFRA_DROPPER_Asyncrat_VBS_February_2022_1 (yara-rule)
- SEKOIA_Rat_Win_Asyncrat (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Asyncrat_C_Sharp (yara-rule)
Reports & references
- decoded.avast.io — Outbreak Of Follina In Australia (report)
- blogs.blackberry.com — Blind Eagle Apt C 36 Targets Colombia (report)
- proofpoint.com — Charting Ta2541S Flight (report)
- Trend Micro — New Apt Group Earth Berberoka Targets Gambling Websites With Old (report)
- Trend Micro — Earth Berberoka Windows Iocs 2.Txt (report)
- botconf.eu — Botconf2022 40 Lunghihorejsi (report)
- research.checkpoint.com — Dangeroussavanna Two Year Long Campaign Targets Financial Institutions In French Speaking Africa (report)
- proofpoint.com — Threat Actor Profile Ta2719 Uses Colorful Lures Deliver Rats Local Languages (report)
- sentinelone.com — Nullbulge Threat Actor Masquerades As Hacktivist Group Rebelling Against Ai (report)
- Cisco Talos — Operation Layover How We Tracked Attack (report)
- assets.virustotal.com — 2021Trends (report)
- intezer.com — Intezer 2020 Go Malware Round Up (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- mp.weixin.qq.com — J A12Sox0K5Toyfaegbv W (report)
- intel471.com — China Cybercrime Undergrond Deepmix Tea Horse Road Great Firewall (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
External references
- mitre-attack — S1087
- Telefonica Snip3 December 2021
- Morphisec Snip3 May 2021
- Cisco Operation Layover September 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy