AsyncRAT

MITRE ATT&CK: S1087 View on attack.mitre.org

Aliases: AsyncRAT

Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
70073 (63441 malicious)
Last IoC activity
2026-09-02 04:24:14
Profile updated
2026-07-07 12:53:17

Context

AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.

Recent IoC activity

63,530 malicious indicators in Maltiverse are attributed to AsyncRAT (S1087). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 3.64.4.198 2026-09-03 4
IP address 3.141.210.37 2026-09-03 6
IP address 213.152.187.230 2026-09-03 7
IP address 3.141.177.1 2026-09-03 6
hostname 2.tcp.ngrok.io 2026-09-03 2
file sample b2d3c2889e056b956bca797b4a62b252f21ac222a59b0e6f471fa3cebac5f4f0 2026-09-03 1
hostname dzonebcp.duckdns.org 2026-09-03 1
IP address 3.127.253.86 2026-09-03 4
IP address 3.69.115.178 2026-09-03 4
IP address 3.68.171.119 2026-09-03 4
hostname 32asinc.duckdns.org 2026-09-03 1
IP address 3.126.224.214 2026-09-03 4
file sample 25e8a1ebec1cc670989e995de71135b5d328cef79320b5566a7c7e8ffcf6400a.bin 2026-09-03 2
file sample 30a23d425d245ac4b63e3dc03159fe63b9f04dd392e104cae7c3051a57696698 2026-09-03 1
file sample bb07eb4d2ed183ff7fa76c6f8b448074cc2179ae7dd0c7e33ee465368b07ebdc.exe 2026-09-03 1
file sample 867c3507625df5294758346af12bfefd87a8bb8c48e9e9e68958652886742797 2026-09-03 3
file sample 869a8a2daa890b414c51af99be794e78d6bd3c60d1450b017e78d421428587c9 2026-09-03 2
hostname donzola.duckdns.org 2026-09-03 2
hostname beckronald.duckdns.org 2026-09-03 1
hostname fmkkaravan.com 2026-09-03 1

Detection coverage

  • 3 YARA rules
  • 263 Sigma rules

Malware & tools used

  • Debugger Evasion (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Native API (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Hidden Window (attack-pattern)
  • System Checks (attack-pattern)
  • Video Capture (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Malicious File (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Keylogging (attack-pattern)
  • Scheduled Task (attack-pattern)

Used by threat actors

  • Operation AkaiRyū (campaign)
  • APT-C-36 (threat-actor)
  • TA2541 (threat-actor)
  • WebDAV Malware Delivery Activity (campaign)

Detection rules

  • SECUINFRA_DROPPER_Asyncrat_VBS_February_2022_1 (yara-rule)
  • SEKOIA_Rat_Win_Asyncrat (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Asyncrat_C_Sharp (yara-rule)

Reports & references

  • decoded.avast.io — Outbreak Of Follina In Australia (report)
  • blogs.blackberry.com — Blind Eagle Apt C 36 Targets Colombia (report)
  • proofpoint.com — Charting Ta2541S Flight (report)
  • Trend Micro — New Apt Group Earth Berberoka Targets Gambling Websites With Old (report)
  • Trend Micro — Earth Berberoka Windows Iocs 2.Txt (report)
  • botconf.eu — Botconf2022 40 Lunghihorejsi (report)
  • research.checkpoint.com — Dangeroussavanna Two Year Long Campaign Targets Financial Institutions In French Speaking Africa (report)
  • proofpoint.com — Threat Actor Profile Ta2719 Uses Colorful Lures Deliver Rats Local Languages (report)
  • sentinelone.com — Nullbulge Threat Actor Masquerades As Hacktivist Group Rebelling Against Ai (report)
  • Cisco Talos — Operation Layover How We Tracked Attack (report)
  • assets.virustotal.com — 2021Trends (report)
  • intezer.com — Intezer 2020 Go Malware Round Up (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • mp.weixin.qq.com — J A12Sox0K5Toyfaegbv W (report)
  • intel471.com — China Cybercrime Undergrond Deepmix Tea Horse Road Great Firewall (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)

External references