logo

German Manufacturing Under Phishing Attacks: Tracking a Stealthy AsyncRAT Campaign 

ID: 322af21e-2573-564a-afbb-9557578d773d

STIX ID: report--322af21e-2573-564a-afbb-9557578d773d

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-26

Author: 4OURUP

...
...

This report analyzes a focused phishing campaign targeting German manufacturing firms that used localized invoice lures and a Dropbox-hosted ZIP containing a malicious .url/.lnk to exploit CVE-2024-43451 via WebDAV, enabling deployment of AsyncRAT and XWorm; sandbox data and multiple related submissions indicate active exploitation, low vendor detections on VirusTotal, and a reproducible attack pattern useful for proactive threat hunting and IOC enrichment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.