logo

Fileless AsyncRAT Distributed Via Clickfix Technique Targeting German Speaking Users

ID: c422ced6-1e1f-51e3-940a-459a6df76bbc

STIX ID: report--c422ced6-1e1f-51e3-940a-459a6df76bbc

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2025-06-16

Date Updated: 2026-04-27

...
...

This report describes a targeted, fileless AsyncRAT campaign that uses a Clickfix-themed webpage to trick German-speaking users into executing an obfuscated PowerShell command which downloads a reversed, base64-encoded C# loader compiled in memory (Add-Type). The payload establishes persistence via HKCU registry keys, creates a TCP reverse shell to namoet.de:4444 for remote control and credential theft, provides extensive IOCs and YARA rules for detection, and recommends blocking suspicious PowerShell execution, registry monitoring, and memory scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.