216.73.217.22

Malware by the (Bit)Bucket: Uncovering AsyncRAT

· Published 10/10/2024 16:05 · Modified 11/10/2024 08:10

Export JSON

Essential information

Published
10/10/2024 16:05
Modified
11/10/2024 08:10
Tags
.net 2024-10-10 asyncrat bitbucket obfuscation powershell rat vbscript
Related entities
15 techniques (mitre), 1 malware

Description

A sophisticated attack campaign using as a legitimate platform to deliver has been uncovered. The multi-stage approach involves a layer, followed by a payload delivery mechanism, and culminates in the execution of . The attackers exploit 's legitimacy and accessibility to host malicious payloads. The campaign employs various evasion techniques, including anti-VM checks and . Persistence is established through Registry Run Keys and Startup Folder shortcuts. provides extensive control over infected machines, enabling remote desktop control, file management, keylogging, and more. The attack demonstrates a high level of sophistication in its use of legitimate platforms and multi-layered techniques.

External references