Cracked Software or Cyber Trap? The Rising Danger of AsyncRAT Malware
ID: 8ff1c015-9b8e-5753-8a94-dd5a80b40c7a
STIX ID: report--8ff1c015-9b8e-5753-8a94-dd5a80b40c7a
Feed Name: McAfee Labs Blog
This McAfee technical analysis describes a multi-stage AsyncRAT campaign (active since March 2024) that lures victims with cracked or portable software (AnyDesk-themed and other fake installers), disables Defender exclusions, drops and reflectively loads obfuscated .NET assemblies, schedules persistence (task named ‘OneNote 67895’ or registry Run key), and connects to a dynamic DNS C2 (orostros.mywire.org); the report includes file hashes, filenames, and step-by-step deobfuscation and debugging details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
