AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery
ID: b8084cb3-978c-5c48-aa25-6fffca5b6f33
STIX ID: report--b8084cb3-978c-5c48-aa25-6fffca5b6f33
Feed Name: cybersecurityNews.com
Forcepoint researchers tracked a phishing-driven AsyncRAT campaign that hides payload delivery behind Dropbox links and TryCloudflare tunnels; a multi-stage chain downloads a malicious Python package whose loader uses Early Bird APC injection to deploy AsyncRAT, VenomRAT, or XWorm. The report provides IoCs (URLs, C2 IPs, and file hashes), describes detection coverage and mitigation recommendations, and warns that abuse of trusted infrastructure will continue to aid evasive malware campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
