AsyncRAT Campaign Continues to Evade Endpoint Detection
Essential information
- Published
- 17/06/2025 20:39
- Modified
- 18/06/2025 11:57
- Tags
- 2025-06-17 asyncrat cloud services cybercriminal endpoint evasion obfuscation phishing purehvnc python scripts remcos remote access trojan trycloudflare venomrat xworm
- Related entities
- 18 techniques (mitre), 5 malware
Description
A wide-ranging phishing campaign has been identified that enables threat actors to bypass traditional security controls and delay detection. The campaign, tracked since 2024, has facilitated remote surveillance, credential theft, lateral movement, data exfiltration, and ransomware across numerous organizations. The likely new or rebranded cybercriminal group behind this campaign uses legitimate services like TryCloudflare to host and deliver highly evasive malware such as AsyncRAT and other Remote Access Trojans. This malware allows threat actors to remotely control infected networks throughout the full attack lifecycle. The campaign targets organizations globally across multiple sectors without industry preference, using widely available malware and difficult-to-detect techniques involving Python scripts, obfuscated batch scripts, trusted cloud services, and dynamic infrastructure.