AsyncRAT Campaign Continues to Evade Endpoint Detection
ID: 5f82f9b7-36c5-54e1-9ebe-023bfe4595ac
STIX ID: report--5f82f9b7-36c5-54e1-9ebe-023bfe4595ac
Feed Name: Halcyon Blog
Halcyon reports a global, sector-agnostic phishing campaign (since early 2024) that abuses legitimate cloud services (notably TryCloudflare tunnels and Dropbox-hosted ZIPs) and obfuscated scripts to deploy Python-based loaders and Remote Access Trojans (AsyncRAT, XWorm, VenomRAT, Remcos), evading traditional EPP/EDR; the report provides specific IOCs (TryCloudflare subdomains and multiple file hashes) and detailed mitigation guidance including blocking tunnels, advanced email filtering, monitoring Python execution, and deploying behavioral EDR/anti-ransomware controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
