AsyncRAT C2 Activity at Internet Scale
ID: 4e584aba-4904-5325-b594-6d3ef31649ca
STIX ID: report--4e584aba-4904-5325-b594-6d3ef31649ca
Feed Name: Censys Blog
Date Published: 2026-01-29
Date Updated: 2026-04-27
Author: Andrew Northern; Principal Security Researcher
AsyncRAT is an open-source .NET remote access trojan widely adopted by criminal operators for persistent access, credential theft (keylogging, memory access, clipboard hijacking), and payload staging; Censys observed 57 internet-exposed AsyncRAT hosts that commonly reuse a default self-signed "AsyncRAT Server" TLS certificate and concentrate on low-cost VPS providers, enabling scalable detection. The report documents technical artifacts (custom TCP C2 on non-standard ports, MessagePack/AES configuration, plugin runtime), delivery vectors (malspam, loader chains, open directories), a static-analysis case study validating AsyncRAT samples, and practical host- and network-based detection and blocking recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
