logo

How Threat Actors Use OneNote to Deploy ASyncRAT

ID: 2778ff82-fd85-5655-a578-05c067182f62

STIX ID: report--2778ff82-fd85-5655-a578-05c067182f62

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

TrustedSec demonstrates how threat actors are embedding ASyncRAT delivery inside Microsoft OneNote documents to enable phishing-based deployments of an open-source remote administration tool, and provides a Sysmon configuration to detect and block the behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.