#AsyncRAT

Malware/Tool

2024-11-19 • 標的型攻撃グループDarkPlumが使用するAsyncRATの亜種について

AsyncRAT is a .NET remote-access trojan used to control Windows hosts, collect system and user information, execute commands, and load operator-provided plugins. In Kimsuky- and Konni-linked infection chains, spear-phishing ZIP archives contained deceptive LNK shortcuts that launched hidden PowerShell loaders, while GitHub, Dropbox, or Google Drive hosted encrypted payloads. Some variants concealed RC4-encrypted assemblies in files presented as PNG images, loaded the assemblies reflectively, and received command-and-control addresses as runtime arguments instead of embedding the destinations directly in the payload.

Tagged Reports

« Back