Malware
AsyncRAT
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victim’s computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques.
Indicators of Compromise 27
Domain camorreado[.]click Domain gitcode[.]com Domain muckcoding[.]com Domain muckdeveloper[.]com Domain pastebin[.]com Domain rlim[.]com Domain t[.]me Filename 7zrr.exe Filename GoFlyDrv.sys Filename L.ps1 Filename Microsoft.exe Filename api.db Filename putty Filename v7.msi GitHub Repo github.com/LastWer/MicrosoftCur GitHub Repo github.com/kaleidora/dnsub-scanning-tool GitHub Repo github.com/tb78/expresso SHA-256 129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff SHA-256 4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4 SHA-256 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 SHA-256 57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629 SHA-256 73c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2 SHA-256 86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0c SHA-256 969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fe SHA-256 a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4 SHA-256 e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63 Registry User [email protected]
MITRE ATT&CK TTPs 37
T1006 T1012 T1014 T1027 T1027.013 T1036.005 T1053.005 T1055 T1055.012 T1055.015 T1057 T1059.001 T1068 T1070.004 T1071.001 T1078 T1082 T1085 T1102.001 T1105 T1112 T1113 T1133 T1140 T1195.001 T1202 T1204.002 T1484.001 T1490 T1543.003 T1548 T1548.002 T1555.003 T1558.003 T1564.003 T1608.001 T1685
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Obfuscated Files or Information
Defense Evasion
Encrypted/Encoded File
Defense Evasion
Match Legitimate Name or Location
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
Process Hollowing
Defense Evasion
ListPlanting
Defense Evasion
Process Discovery
Discovery
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
T1085
Dead Drop Resolver
Command And Control
Ingress Tool Transfer
Command And Control
Modify Registry
Defense Evasion
Screen Capture
Collection
External Remote Services
Persistence
Deobfuscate/Decode Files or Information
Defense Evasion
Compromise Software Dependencies and Development Tools
Initial Access
Indirect Command Execution
Defense Evasion
Malicious File
Execution
Group Policy Modification
Defense Evasion
Inhibit System Recovery
Impact
Windows Service
Persistence
Abuse Elevation Control Mechanism
Privilege Escalation
Bypass User Account Control
Privilege Escalation
Credentials from Web Browsers
Credential Access
Kerberoasting
Credential Access
Hidden Window
Defense Evasion
Upload Malware
Resource Development
T1685
Source Articles
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1d ago
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
A malicious Go module, github.com/kaleidora/dnsub-scanning-tool, serves as a lure to deliver a multi-stage Windows malware chain involving hidden PowerShell execution and encrypted payload resolution via public dead drops. The campaign, tracked as Operation Muck and Load, leverages a network of 222 GitHub repositories across 190 accounts to create credibility and scale for malicious or deceptive software projects. These repositories use synthetic activity to appear recently maintained, facilitating social engineering and malware distribution. The final payload includes RATs such as AsyncRAT, Quasar, and Remcos, along with infostealers like Vidar, enabling credential theft, screen capture, and persistence.
socket-dev
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·2w ago