AsyncRAT Campaigns Uncovered: How Attackers Abuse ScreenConnect and Open Directories
ID: 5afcadb9-0678-5824-844e-f0103e609561
STIX ID: report--5afcadb9-0678-5824-844e-f0103e609561
Feed Name: Hunt.io Blog
This report documents a sustained 2024–2025 campaign abusing trojanized ConnectWise ScreenConnect and ClickOnce-style installers to deliver AsyncRAT and a custom PowerShell RAT via open directories and phishing redirect chains; it enumerates multiple infrastructure hosts and domains, file- and container-hash IOCs, dual execution paths (in-memory .NET load vs native DLL injection via libPK.dll), aggressive persistence (scheduled tasks), port/TLS-based C2 tradecraft, and provides detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
