logo

AsyncRAT Campaign Continues to Evade Endpoint Detection

ID: 5f82f9b7-36c5-54e1-9ebe-023bfe4595ac

STIX ID: report--5f82f9b7-36c5-54e1-9ebe-023bfe4595ac

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon reports a global, sector-agnostic phishing campaign (since early 2024) that abuses legitimate cloud services (notably TryCloudflare tunnels and Dropbox-hosted ZIPs) and obfuscated scripts to deploy Python-based loaders and Remote Access Trojans (AsyncRAT, XWorm, VenomRAT, Remcos), evading traditional EPP/EDR; the report provides specific IOCs (TryCloudflare subdomains and multiple file hashes) and detailed mitigation guidance including blocking tunnels, advanced email filtering, monitoring Python execution, and deploying behavioral EDR/anti-ransomware controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.