logo

Fileless Malware Deploys Advanced RAT via Legitimate Tools

ID: 27249282-6422-50fc-8150-b5bb0f249b92

STIX ID: report--27249282-6422-50fc-8150-b5bb0f249b92

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-09-11

Date Updated: 2026-04-22

...
...

Researchers uncovered a fileless campaign that abused a compromised ScreenConnect client to run a VBScript/PowerShell loader which loaded payloads into memory and invoked a .NET assembly (Obfuscator.dll) to deploy AsyncRAT. The malware establishes persistence (scheduled task named “Skype Updater”), disables Windows logging, communicates with C2 domains (e.g., 3osch20.duckdns.org), and exfiltrates system information, credentials, browser artifacts and keystrokes, making detection and remediation difficult.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.