Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

AsyncRAT’s Complex Infection Chain

November 6, 2023
Reading Time: 7 mins read
in Alerts

A detailed analysis has uncovered the sophisticated infection chain of AsyncRAT, a potent malware strain known as an “Asynchronous Remote Access Trojan.” This malware specializes in compromising computer systems and extracting sensitive information, and what makes it particularly formidable is its stealthy behavior.

Furthermore, McAfee Labs has recently identified an ongoing AsyncRAT campaign that leverages various file types, including PowerShell, Windows Script Files (WSF), VBScript (VBS), and more, to elude antivirus detection mechanisms.

Additionally, the intricate infection chain starts with a malicious URL contained within a spam email, which triggers the download of an HTML file. This HTML file, in turn, contains an embedded ISO file, housing a WSF script. This WSF script connects to multiple URLs and executes various files in formats such as PowerShell, VBS, and BAT. These executed files serve to perform a process injection into RegSvcs.exe, a legitimate Microsoft .NET utility, allowing the attacker to conceal their activities within a trusted system application.

Following this initial stage, the PowerShell script proceeds to create a folder in the ProgramData directory and extracts files. These files are executed, leading to an intricate chain of execution involving different file types. This complexity helps evade both static and behavior-based antivirus detection. The final phase of the attack involves injecting a Portable Executable (PE) file into “C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe”.

Subsequently, the compromised RegSvcs.exe establishes a connection to an AsyncRAT server. The malware exhibits keylogging capabilities, records user activities, steals credentials, browser data, and crypto-related information, which is transmitted over TCP to a specific IP address and port. This multifaceted infection chain showcases the attackers‘ ability to gain remote control and successfully pilfer sensitive data while maintaining a covert presence.

Reference:
  • Unmasking AsyncRAT New Infection Chain
Tags: AsyncRATCyber Alerts 2023CybersecurityMalwareMcAfeeNovember 2023Remote Access TrojanSensitive dataTrojanVulnerabilities
ADVERTISEMENT

Related Posts

Fake PyPI Login Site Steals Credentials

Fake PyPI Login Site Steals Credentials

September 26, 2025
Fake PyPI Login Site Steals Credentials

Google Warns of BRICKSTORM Malware

September 26, 2025
Fake PyPI Login Site Steals Credentials

Hidden WordPress Backdoors Create Admins

September 26, 2025
BadIIS Malware Spreads Via SEO Poisoning

Hackers Target AWS and Steal Credentials

September 24, 2025
BadIIS Malware Spreads Via SEO Poisoning

SonicWall SMA100 Update Removes Rootkit

September 24, 2025
BadIIS Malware Spreads Via SEO Poisoning

BadIIS Malware Spreads Via SEO Poisoning

September 24, 2025

Latest Alerts

Fake PyPI Login Site Steals Credentials

Google Warns of BRICKSTORM Malware

Hidden WordPress Backdoors Create Admins

Hackers Target AWS and Steal Credentials

SonicWall SMA100 Update Removes Rootkit

BadIIS Malware Spreads Via SEO Poisoning

Subscribe to our newsletter

    Latest Incidents

    Indian Bank Transfer Records Exposed

    Chinese Cyberspies Hit US Defense Firms

    Neon App Shuts Down After Data Leak

    Boyd Gaming Reports Data Breach After Attack

    Morrisroe UK Company Hit By Cyber Attack

    GeoServer Flaw Breaches US Agency Network

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial