logo

AsyncRAT C2 Activity at Internet Scale

ID: 4e584aba-4904-5325-b594-6d3ef31649ca

STIX ID: report--4e584aba-4904-5325-b594-6d3ef31649ca

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Andrew Northern; Principal Security Researcher

...
...

AsyncRAT is an open-source .NET remote access trojan widely adopted by criminal operators for persistent access, credential theft (keylogging, memory access, clipboard hijacking), and payload staging; Censys observed 57 internet-exposed AsyncRAT hosts that commonly reuse a default self-signed "AsyncRAT Server" TLS certificate and concentrate on low-cost VPS providers, enabling scalable detection. The report documents technical artifacts (custom TCP C2 on non-standard ports, MessagePack/AES configuration, plugin runtime), delivery vectors (malspam, loader chains, open directories), a static-analysis case study validating AsyncRAT samples, and practical host- and network-based detection and blocking recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.