logo

Cracked Software or Cyber Trap? The Rising Danger of AsyncRAT Malware

ID: 8ff1c015-9b8e-5753-8a94-dd5a80b40c7a

STIX ID: report--8ff1c015-9b8e-5753-8a94-dd5a80b40c7a

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2024-09-19

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee technical analysis describes a multi-stage AsyncRAT campaign (active since March 2024) that lures victims with cracked or portable software (AnyDesk-themed and other fake installers), disables Defender exclusions, drops and reflectively loads obfuscated .NET assemblies, schedules persistence (task named ‘OneNote 67895’ or registry Run key), and connects to a dynamic DNS C2 (orostros.mywire.org); the report includes file hashes, filenames, and step-by-step deobfuscation and debugging details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.