Yet Another TA558 Campaign Targets South America’s Hospitality Industry With AsyncRAT
ID: 351dbafe-e457-560a-a7e7-49fcbc2a230f
STIX ID: report--351dbafe-e457-560a-a7e7-49fcbc2a230f
Feed Name: WatchGuard Secplicity Blog
Threat Score
This report analyzes a targeted phishing campaign (attributed to TA558) that uses obfuscated JavaScript and PowerShell droppers (collectively called "kimkarden" variants) to deliver an AsyncRAT remote access trojan; the researcher details the multi-stage infection chain, deobfuscation steps, helper DLL behavior (using Regsvcs/Msbuild), extracted C2 domains, file/URL/port IoCs, and related hosting infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
