logo

Yet Another TA558 Campaign Targets South America’s Hospitality Industry With AsyncRAT

ID: 351dbafe-e457-560a-a7e7-49fcbc2a230f

STIX ID: report--351dbafe-e457-560a-a7e7-49fcbc2a230f

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2024-06-17

Date Updated: 2026-05-01

Author: The Editor

...
...

This report analyzes a targeted phishing campaign (attributed to TA558) that uses obfuscated JavaScript and PowerShell droppers (collectively called "kimkarden" variants) to deliver an AsyncRAT remote access trojan; the researcher details the multi-stage infection chain, deobfuscation steps, helper DLL behavior (using Regsvcs/Msbuild), extracted C2 domains, file/URL/port IoCs, and related hosting infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.