#AsyncRAT
Malware/Tool
2024-11-19 • 標的型攻撃グループDarkPlumが使用するAsyncRATの亜種について
AsyncRAT is a .NET remote-access trojan used to control Windows hosts, collect system and user information, execute commands, and load operator-provided plugins. In Kimsuky- and Konni-linked infection chains, spear-phishing ZIP archives contained deceptive LNK shortcuts that launched hidden PowerShell loaders, while GitHub, Dropbox, or Google Drive hosted encrypted payloads. Some variants concealed RC4-encrypted assemblies in files presented as PNG images, loaded the assemblies reflectively, and received command-and-control addresses as runtime arguments instead of embedding the destinations directly in the payload.
-
7
Tagged Reports
-
5
Unique Authors
-
629
Active Days