logo

Null-AMSI Evading Security To Deploy AsyncRAT

ID: c28aad37-b83b-5e42-a7ec-7a0832183a82

STIX ID: report--c28aad37-b83b-5e42-a7ec-7a0832183a82

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-02-21

Date Updated: 2026-07-16

...
...

This CRIL report describes a malicious campaign that uses deceptive LNK wallpaper shortcuts to launch obfuscated PowerShell scripts that download additional stages, bypass AMSI and ETW using a Null‑AMSI-style technique (noted to contain Portuguese comments), decrypt AES/GZIP-encoded payloads in memory, and ultimately load AsyncRAT for remote access; the report provides detailed technical analysis, persistence and evasion techniques, IOCs (file hashes, URLs, and a C2 IP), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.