logo

From Spam to AsyncRAT: Tracking the Surge in Non-PE Cyber Threats

ID: d02c33e2-de8a-5a5a-b0ec-14c98041e74f

STIX ID: report--d02c33e2-de8a-5a5a-b0ec-14c98041e74f

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2024-05-08

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs analyzes an AsyncRAT campaign that uses a spam-delivered HTML to fetch a WSF which stages multiple scripts (VBS/JS/BAT/PS1), drops and extracts a ZIP of dropper files, installs a scheduled task named "cafee" to run app.js for persistence, decodes and loads PE payloads (DLL and EXE), performs process injection into aspnet_compiler.exe, and establishes C2 communications; the report provides detailed IOCs (SHA256 hashes and C2 URLs) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.