216.73.217.22

AsyncRAT Campaign Continues to Evade Endpoint Detection

· Published 17/06/2025 20:39 · Modified 18/06/2025 11:57

Export JSON

Essential information

Published
17/06/2025 20:39
Modified
18/06/2025 11:57
Tags
2025-06-17 asyncrat cloud services cybercriminal endpoint evasion obfuscation phishing purehvnc python scripts remcos remote access trojan trycloudflare venomrat xworm
Related entities
18 techniques (mitre), 5 malware

Description

A wide-ranging campaign has been identified that enables threat actors to bypass traditional security controls and delay detection. The campaign, tracked since 2024, has facilitated remote surveillance, credential theft, lateral movement, data exfiltration, and ransomware across numerous organizations. The likely new or rebranded group behind this campaign uses legitimate services like to host and deliver highly evasive malware such as and other Remote Access Trojans. This malware allows threat actors to remotely control infected networks throughout the full attack lifecycle. The campaign targets organizations globally across multiple sectors without industry preference, using widely available malware and difficult-to-detect techniques involving , obfuscated batch scripts, trusted , and dynamic infrastructure.

External references