logo

ThreatLabz

ID: 3caeb3f7-3ec9-547c-b656-4f4e9985603a

STIX ID: report--3caeb3f7-3ec9-547c-b656-4f4e9985603a

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Case study of a OneNote-based malware campaign (since December 2022) that distributes Remote Access Trojans including AsyncRAT by embedding an obfuscated batch file and PowerShell payloads inside .one documents; researchers recovered and deobfuscated encrypted blobs (base64/AES/gzip), extracted PE files packed with AgileDotNet, and identified AsyncRAT after unpacking with de4dot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.