Null-AMSI Evading Security To Deploy AsyncRAT
ID: c28aad37-b83b-5e42-a7ec-7a0832183a82
STIX ID: report--c28aad37-b83b-5e42-a7ec-7a0832183a82
Feed Name: Cyble Blog
This CRIL report describes a malicious campaign that uses deceptive LNK wallpaper shortcuts to launch obfuscated PowerShell scripts that download additional stages, bypass AMSI and ETW using a Null‑AMSI-style technique (noted to contain Portuguese comments), decrypt AES/GZIP-encoded payloads in memory, and ultimately load AsyncRAT for remote access; the report provides detailed technical analysis, persistence and evasion techniques, IOCs (file hashes, URLs, and a C2 IP), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
