216.73.216.6

Fileless AsyncRAT Distributed Via Clickfix Technique Targeting German Speaking Users

· Published 16/06/2025 13:03 · Modified 16/06/2025 15:24

Export JSON

Essential information

Published
16/06/2025 13:03
Modified
16/06/2025 15:24
Tags
2025-06-16 asyncrat c2 clickfix fileless german-speaking in-memory execution obfuscation powershell
Related entities
9 techniques (mitre), 1 malware, 1 others

Description

A campaign is targeting users through -themed websites. The attack uses a fake 'I'm not a robot' prompt to execute malicious code, which downloads and runs obfuscated C# code in memory. This technique enables full remote access, credential theft, and data exfiltration without leaving traces on the disk. The malware establishes persistence via registry keys and communicates with a command and control server on port 4444. The campaign has been active since at least April 2025, primarily affecting regions. Mitigation strategies include blocking suspicious activity, monitoring registry changes, and implementing in-memory scanning for threats.

External references