Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

AsyncRAT’s Complex Infection Chain

November 6, 2023
Reading Time: 7 mins read
in Alerts

A detailed analysis has uncovered the sophisticated infection chain of AsyncRAT, a potent malware strain known as an “Asynchronous Remote Access Trojan.” This malware specializes in compromising computer systems and extracting sensitive information, and what makes it particularly formidable is its stealthy behavior.

Furthermore, McAfee Labs has recently identified an ongoing AsyncRAT campaign that leverages various file types, including PowerShell, Windows Script Files (WSF), VBScript (VBS), and more, to elude antivirus detection mechanisms.

Additionally, the intricate infection chain starts with a malicious URL contained within a spam email, which triggers the download of an HTML file. This HTML file, in turn, contains an embedded ISO file, housing a WSF script. This WSF script connects to multiple URLs and executes various files in formats such as PowerShell, VBS, and BAT. These executed files serve to perform a process injection into RegSvcs.exe, a legitimate Microsoft .NET utility, allowing the attacker to conceal their activities within a trusted system application.

Following this initial stage, the PowerShell script proceeds to create a folder in the ProgramData directory and extracts files. These files are executed, leading to an intricate chain of execution involving different file types. This complexity helps evade both static and behavior-based antivirus detection. The final phase of the attack involves injecting a Portable Executable (PE) file into “C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe”.

Subsequently, the compromised RegSvcs.exe establishes a connection to an AsyncRAT server. The malware exhibits keylogging capabilities, records user activities, steals credentials, browser data, and crypto-related information, which is transmitted over TCP to a specific IP address and port. This multifaceted infection chain showcases the attackers‘ ability to gain remote control and successfully pilfer sensitive data while maintaining a covert presence.

Reference:
  • Unmasking AsyncRAT New Infection Chain
Tags: AsyncRATCyber Alerts 2023CybersecurityMalwareMcAfeeNovember 2023Remote Access TrojanSensitive dataTrojanVulnerabilities
ADVERTISEMENT

Related Posts

New Malware Uses Prompts To Trick AI Tools

Fake Job Offers Hide North Korean Malware

June 26, 2025
New Malware Uses Prompts To Trick AI Tools

New Malware Uses Prompts To Trick AI Tools

June 26, 2025
New Malware Uses Prompts To Trick AI Tools

New Zero Day Flaw Hits Citrix NetScaler

June 26, 2025
OneClik Malware Attacks Energy Sector Firms

Hackers Abuse Trezor Support For Phishing

June 25, 2025
OneClik Malware Attacks Energy Sector Firms

FileFix Attack Turns Explorer Into Weapon

June 25, 2025
OneClik Malware Attacks Energy Sector Firms

OneClik Malware Attacks Energy Sector Firms

June 25, 2025

Latest Alerts

Fake Job Offers Hide North Korean Malware

New Malware Uses Prompts To Trick AI Tools

New Zero Day Flaw Hits Citrix NetScaler

Hackers Abuse Trezor Support For Phishing

FileFix Attack Turns Explorer Into Weapon

OneClik Malware Attacks Energy Sector Firms

Subscribe to our newsletter

    Latest Incidents

    Resupply DeFi Protocol Hacked For $9.6M

    Cyberattack Hits South Tyrol Emergency Ops

    UK’s Glasgow City Council Hit By Cyberattack

    Columbia University Probes Major IT Outage

    Mainline Health Breach Hits 101,000 Patients

    Porto Nacional City Hall Hit by Ransomware

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial