Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

AsyncRAT’s Complex Infection Chain

November 6, 2023
Reading Time: 7 mins read
in Alerts

A detailed analysis has uncovered the sophisticated infection chain of AsyncRAT, a potent malware strain known as an “Asynchronous Remote Access Trojan.” This malware specializes in compromising computer systems and extracting sensitive information, and what makes it particularly formidable is its stealthy behavior.

Furthermore, McAfee Labs has recently identified an ongoing AsyncRAT campaign that leverages various file types, including PowerShell, Windows Script Files (WSF), VBScript (VBS), and more, to elude antivirus detection mechanisms.

Additionally, the intricate infection chain starts with a malicious URL contained within a spam email, which triggers the download of an HTML file. This HTML file, in turn, contains an embedded ISO file, housing a WSF script. This WSF script connects to multiple URLs and executes various files in formats such as PowerShell, VBS, and BAT. These executed files serve to perform a process injection into RegSvcs.exe, a legitimate Microsoft .NET utility, allowing the attacker to conceal their activities within a trusted system application.

Following this initial stage, the PowerShell script proceeds to create a folder in the ProgramData directory and extracts files. These files are executed, leading to an intricate chain of execution involving different file types. This complexity helps evade both static and behavior-based antivirus detection. The final phase of the attack involves injecting a Portable Executable (PE) file into “C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe”.

Subsequently, the compromised RegSvcs.exe establishes a connection to an AsyncRAT server. The malware exhibits keylogging capabilities, records user activities, steals credentials, browser data, and crypto-related information, which is transmitted over TCP to a specific IP address and port. This multifaceted infection chain showcases the attackers‘ ability to gain remote control and successfully pilfer sensitive data while maintaining a covert presence.

Reference:
  • Unmasking AsyncRAT New Infection Chain
Tags: AsyncRATCyber Alerts 2023CybersecurityMalwareMcAfeeNovember 2023Remote Access TrojanSensitive dataTrojanVulnerabilities
ADVERTISEMENT

Related Posts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

May 14, 2025
Microsoft Defender Bug Allows SYSTEM Access

Devs Hit By PyPI Solana Token Secret Theft

May 14, 2025
Microsoft Defender Bug Allows SYSTEM Access

Microsoft Defender Bug Allows SYSTEM Access

May 14, 2025
Apple Fixes Critical Bugs in iOS and MacOS

Hackers Exploit Output Messenger Zero-Day

May 13, 2025
Apple Fixes Critical Bugs in iOS and MacOS

ASUS Fixes Critical Flaws in DriverHub

May 13, 2025
Apple Fixes Critical Bugs in iOS and MacOS

Apple Fixes Critical Bugs in iOS and MacOS

May 13, 2025

Latest Alerts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

Devs Hit By PyPI Solana Token Secret Theft

Hackers Exploit Output Messenger Zero-Day

ASUS Fixes Critical Flaws in DriverHub

Apple Fixes Critical Bugs in iOS and MacOS

Subscribe to our newsletter

    Latest Incidents

    Alabama Cybersecurity Event Hits Services

    Andy Frain Data Breach Impacts 100k People

    Hong Kong DSC Hit By Ransomware Attack

    Alleged Steam Breach Exposes 89M Records

    Ulhasnagar Municipal Corporation Hacked

    Madison County Iowa Systems Disrupted

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial