216.73.217.22

AsyncRAT Reloaded: Using Python and TryCloudflare for Malware Delivery Again

· Published 01/02/2025 08:19 · Modified 04/02/2025 15:14

Export JSON

Essential information

Published
01/02/2025 08:19
Modified
04/02/2025 15:14
Tags
2025-02-01 asyncrat dropbox evasion techniques phishing process injection python remote access trojan trycloudflare venomrat xworm
Related entities
11 techniques (mitre), 3 malware

Description

A new malware campaign has been identified, utilizing malicious payloads delivered through quick tunnels and packages. The attack chain begins with a email containing a URL, leading to a ZIP file with an internet shortcut. This triggers a series of downloads, ultimately executing malware via scripts. The campaign employs legitimate infrastructure like and to evade detection. It uses a multi-step process involving LNK, JavaScript, and BAT files, culminating in the extraction of malicious scripts. The attackers use techniques to inject shellcode into legitimate processes like notepad.exe and explorer.exe. This sophisticated approach highlights the evolving nature of cyber threats and the exploitation of legitimate services for malicious purposes.

External references