AsyncRAT Introduces a New Delivery Technique

Share This Post

Morphisec, through its breach prevention with Moving Target Defense technology, has identified a new, sophisticated campaign delivery which has been successfully evading the radar of many security vendors. Through a simple email phishing tactic with an html attachment, threat attackers are delivering AsyncRAT (a remote access trojan) designed to remotely monitor and control its infected computers through a secure, encrypted connection. This campaign has been in effect for a period of 4 to 5 months, with the lowest detection rates as presented through VirusTotal.

Morphisec backtraced the campaign to September 12, 2021. This campaign continued its evolution while delivering formally known crypter as a service, such as HCrypt and Alosh. This blog post explains the campaign delivery vector in detail.

https://blog.morphisec.com/asyncrat-new-delivery-technique-new-threat-campaign



Reach out to our incident response team for help

More To Explore

Information Security News – 09/28/26

ShinyHunters Bypasses Firewall Protections in Oracle PeopleSoft Attacks Article Link: https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/ What does this mean for me? Citrix Confirms Two NetScaler Zero-Days Exploited in Attacks

Information Security News – 09/21/2026

Chinese hackers use SparroWocky malware in govt espionage attacks Article Link: https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/ What does this mean for me? CISA decides weekly vulnerability bulletin isn’t necessary

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.