Fileless AsyncRAT Distributed Via Clickfix Technique Targeting German Speaking Users
ID: c422ced6-1e1f-51e3-940a-459a6df76bbc
STIX ID: report--c422ced6-1e1f-51e3-940a-459a6df76bbc
Feed Name: CloudSEK Blog
This report describes a targeted, fileless AsyncRAT campaign that uses a Clickfix-themed webpage to trick German-speaking users into executing an obfuscated PowerShell command which downloads a reversed, base64-encoded C# loader compiled in memory (Add-Type). The payload establishes persistence via HKCU registry keys, creates a TCP reverse shell to namoet.de:4444 for remote control and credential theft, provides extensive IOCs and YARA rules for detection, and recommends blocking suspicious PowerShell execution, registry monitoring, and memory scanning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
