AsyncRAT is an open-source remote access trojan (RAT) first identified in 2019, written in C# and publicly available on GitHub (source: MITRE ATT&CK S0539). It is categorized as a RAT used by various cybercriminal groups for remote surveillance, data theft, and as a foothold for ransomware operations. The malware’s operators are not a single group; it is distributed as a commodity tool through phishing emails and malicious downloads.
AsyncRAT communicates with its command-and-control (C2) server over encrypted TCP on ports 443 or 8800, using a bespoke protocol. It employs process injection (MITRE ATT&CK T1055), code obfuscation via ConfuserEx, and anti-debugging techniques to evade analysis. Persistence is achieved by adding registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or creating scheduled tasks. Its feature set includes keylogging, screen capture, audio recording, file exfiltration, remote shell (T1059), and clipboard monitoring. AsyncRAT supports a plugin architecture for loading additional modules like password stealers or cryptocurrency clippers.
Since its GitHub release, AsyncRAT has been observed in campaigns targeting U.S. healthcare organizations in 2021 (reported by BleepingComputer) and a 2023 campaign alongside AgentTesla detected by Fortinet FortiGuard Labs. No CVEs are specific to AsyncRAT, but it is often delivered via exploits such as CVE-2021-40444 (MSHTML) or CVE-2023-38831 (WinRAR). Law enforcement has not targeted the open-source developers, but several C2 domains have been taken down via court orders.
Common indicators include the mutex name AsyncMutex (also “AsyncRAT_Mutex”) documented by Trend Micro. Registry persistence keys, such as “AsyncRAT” under HKCURun, are frequently used. Network IOCs include connections to dynamically generated domains (e.g., *.duckdns.org) on non-standard TCP ports; known file hashes are cataloged on VirusTotal (e.g., SHA256: 2c5a3c7f8b... from Any.Run reports). The malware may use a User-Agent string mimicking “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36” to blend in.
AsyncRAT enables attackers to exfiltrate sensitive data (passwords, financial information), capture keystrokes, and maintain persistent remote access, often leading to ransomware deployment or business email compromise. According to CISA advisories, healthcare, education, and manufacturing sectors have been targeted. While direct financial losses are rarely attributed solely to AsyncRAT, it frequently serves as an initial access vector for larger extortion campaigns, with recovery costs often exceeding $1 million per incident.
Mitigation includes enabling Windows Defender Attack Surface Reduction rules, deploying EDR solutions (e.g., SentinelOne, CrowdStrike), and blocking execution of unsigned .NET assemblies. Organizations should monitor for anomalous outbound TCP connections to port 8800 and implement phishing awareness training. The CISA “Ransomware Guide” provides additional recommended controls for defending against RAT-based intrusions.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.