A malware campaign has been detected distributing a Trojan RAT called AsyncRAT . It is spread via Python payloads and the use of TryCloudflare tunnels , making the attack even more sophisticated and difficult to detect.
See also: Phishing: PNGPlug Loader distributes ValleyRAT malware

The starting point of a complex, multi-stage AsyncRAT attack chain is a phishing email that includes a link to Dropbox. Once clicked, a ZIP file is downloaded, triggering the process.
Inside the file is an Internet link (URL), which acts as a bridge to a Windows shortcut file (LNK). This file is responsible for further spreading the infection, while the recipient is presented with a seemingly innocent PDF document as bait.
The LNK file is retrieved via a TryCloudflare URL, which is embedded in the URL file. TryCloudflare is a trusted service offered by Cloudflare, allowing web servers to be exposed to the Internet without the need to open ports. Through this service, a dedicated communication channel is created, ensuring that traffic is transferred securely and seamlessly to the server.
See also: NonEuclid Trojan: New advanced RAT malware
The LNK file, in turn, triggers PowerShell to execute JavaScript code hosted in the same location, which in turn leads to a batch script (BAT) capable of downloading another ZIP file. The new ZIP file you downloaded contains a Python payload designed to launch and execute several malware families, including AsyncRAT, Venom RAT and XWorm.

It is worth noting that a small variation of the same infection sequence was discovered last year and spread AsyncRAT, GuLoader, PureLogs Stealer, Remcos RAT, Venom RAT and XWorm.
The development comes amid a rise in phishing that use phishing-as-a-service (PhaaS) toolkits to conduct account takeover attacks by directing users to fake landing pages that mimic the login pages of trusted platforms such as Microsoft, Google, Apple, and GitHub.
See also: Bitter Group targets defense sector with WmRAT and MiyaRAT malware
Phishing-as-a-Service (PhaaS) has emerged as a worrying trend in the cybersecurity world. This service allows malicious users, even without technical knowledge, to carry out phishing attacks, using tools and infrastructure provided by specialized cybercriminals. With a wide range of tools and capabilities, such as ready-made fraudulent websites and automated platforms, PhaaS lowers the barriers to implementing social engineering. This democratization of cyberattacks increases the risk to organizations and individuals, making it necessary to strengthen education and security solutions.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
