Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

AsyncRAT’s Complex Infection Chain

November 6, 2023
Reading Time: 7 mins read
in Alerts

A detailed analysis has uncovered the sophisticated infection chain of AsyncRAT, a potent malware strain known as an “Asynchronous Remote Access Trojan.” This malware specializes in compromising computer systems and extracting sensitive information, and what makes it particularly formidable is its stealthy behavior.

Furthermore, McAfee Labs has recently identified an ongoing AsyncRAT campaign that leverages various file types, including PowerShell, Windows Script Files (WSF), VBScript (VBS), and more, to elude antivirus detection mechanisms.

Additionally, the intricate infection chain starts with a malicious URL contained within a spam email, which triggers the download of an HTML file. This HTML file, in turn, contains an embedded ISO file, housing a WSF script. This WSF script connects to multiple URLs and executes various files in formats such as PowerShell, VBS, and BAT. These executed files serve to perform a process injection into RegSvcs.exe, a legitimate Microsoft .NET utility, allowing the attacker to conceal their activities within a trusted system application.

Following this initial stage, the PowerShell script proceeds to create a folder in the ProgramData directory and extracts files. These files are executed, leading to an intricate chain of execution involving different file types. This complexity helps evade both static and behavior-based antivirus detection. The final phase of the attack involves injecting a Portable Executable (PE) file into “C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe”.

Subsequently, the compromised RegSvcs.exe establishes a connection to an AsyncRAT server. The malware exhibits keylogging capabilities, records user activities, steals credentials, browser data, and crypto-related information, which is transmitted over TCP to a specific IP address and port. This multifaceted infection chain showcases the attackers‘ ability to gain remote control and successfully pilfer sensitive data while maintaining a covert presence.

Reference:
  • Unmasking AsyncRAT New Infection Chain
Tags: AsyncRATCyber Alerts 2023CybersecurityMalwareMcAfeeNovember 2023Remote Access TrojanSensitive dataTrojanVulnerabilities
ADVERTISEMENT

Related Posts

FBI Seizes Multiple Game Piracy Sites

XORIndex Malware DPRK npm Attack

July 15, 2025
FBI Seizes Multiple Game Piracy Sites

NCC Urges Windows 11 Upgrade Cyber Defenses

July 15, 2025
FBI Seizes Multiple Game Piracy Sites

FBI Seizes Multiple Game Piracy Sites

July 15, 2025
Wing FTP Server RCE Flaw Exploited

WinRAR Zero-Day Exploit $80K on Dark Web

July 14, 2025
Wing FTP Server RCE Flaw Exploited

Google Gemini Flaw Hijacks Email Summaries

July 14, 2025
Wing FTP Server RCE Flaw Exploited

Wing FTP Server RCE Flaw Exploited

July 14, 2025

Latest Alerts

NCC Urges Windows 11 Upgrade Cyber Defenses

FBI Seizes Multiple Game Piracy Sites

XORIndex Malware DPRK npm Attack

WinRAR Zero-Day Exploit $80K on Dark Web

Google Gemini Flaw Hijacks Email Summaries

Wing FTP Server RCE Flaw Exploited

Subscribe to our newsletter

    Latest Incidents

    Elmo Impersonator Posts Antisemitic Content

    PET Imaging Phishing Attack Hits

    Louis Vuitton Data Breach Global Impact

    Supermarket Cyberattack Prompts Warning

    China Hacker Suspected in DC Law Firm Breach

    nius.de Cyberattack Leaks User Data

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial