The Middle East and North Africa have been targeted by a new malware campaign, delivering a modified version of AsyncRAT. The attacks have been taking place since September 2024.

According to researchers at Positive Technologies, the malicious campaign leverages social media to distribute the malware and is reportedly tied to the current geopolitical climate in the region. “The attackers are hosting malware on legitimate online file-sharing accounts or Telegram channels that have been created specifically for this purpose.”
The campaign is said to have claimed over 900 victims since the fall of 2024, indicating that it is not particularly targeted. The majority of victims are located in Libya, Saudi Arabia, Egypt, Turkey, the United Arab Emirates, Qatar, and Tunisia.
See also: Phantom Goblin delivers stealer malware
The malicious activity is attributed to a group called Desert Dexter and was discovered in February 2025. It mainly involves creating temporary Facebook accounts and news feeds. These accounts are then used to post ads containing links to a file-sharing service or Telegram channel.
The links redirect users to a version of the AsyncRAT malware that has been modified to include an offline keylogger, search for 16 different crypto extensions and applications and communicate with a Telegram bot.
The kill chain begins with a RAR archive that contains either a batch script or a JavaScript file. These are programmed to execute a PowerShell script that is responsible for triggering the second stage of the attack.
See also: BadBox malware disrupted on 500,000 infected Android devices
It terminates processes related to various .NET services that could prevent the malware from starting, deletes files with the BAT, PS1, and VBS extensions from the “C:\ProgramData\WindowsHost” and “C:\Users\Public” folders, and creates a new VBS file in C:\ProgramData\WindowsHost and BAT and PS1 files in C:\Users\Public.
The script then establishes persistence on the system, collects and exports system information to a Telegram bot, takes screenshots, and finally launches the AsyncRAT payload by inserting it into the executable file “aspnet_compiler.exe”.
Further analysis of the messages sent to the Telegram bot revealed screenshots of the attacker’s own desktop called “DEXTERMSI”. Thus, the PowerShell script as well as a tool called Luminosity Link RAT. The Telegram bot also contains a link to a Telegram channel called “dexterlyly”, which suggests that the threat actor may be from Libya. The channel was created on October 5, 2024.
See also: New polyglot malware hits aviation and satellite communications companies
“The majority of victims are ordinary users, including workers in the following sectors: oil production, construction, information technology [and] agriculture,” the researchers said.
“The tools used by Desert Dexter are not particularly sophisticated, but the combination of Facebook ads with legitimate services and references to the geopolitical situation has led to the infection of many devices“.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Malware protection
The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.
Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.
You should also be careful with emails and messages you receive. Many RAT malware (AsyncRAT malware) are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.
Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.
Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.
Source: thehackernews.com
