logo

Analyzing a a Multi-Stage AsyncRAT Campaign via Managed Detection and Response

ID: 1d8b4171-d205-595e-bd33-a27b8e6f3206

STIX ID: report--1d8b4171-d205-595e-bd33-a27b8e6f3206

Feed Name: TrendAI Security Blog

Threat Score
75/100

Date Published: 2026-01-01

Date Updated: 2026-08-14

...
...

This report analyzes a multi-stage AsyncRAT campaign that begins with phishing emails delivering a double-extension Internet Shortcut (*.pdf.url) which redirects to TryCloudflare WebDAV hosts; attackers download and install an embedded Python environment, execute staged scripts and batch files (as.wsh, anc.wsf, vio.bat, xeno.bat), establish persistence via startup batch files (ahke.bat, olsm.bat), and perform polymorphic APC code injection into explorer.exe using ne.py and new.bin (Donut-generated shellcode) to deploy AsyncRAT, while abusing Cloudflare free-tier infrastructure to evade detection and providing numerous IOCs and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.