HomeSecurityDesert Dexter infects 900 victims with AsyncRAT

Desert Dexter infects 900 victims with AsyncRAT

The Middle East and North Africa have been targeted by a new malware campaign, delivering a modified version of AsyncRAT. The attacks have been taking place since September 2024.

Desert Dexter infects 900 victims with AsyncRAT

According to researchers at Positive Technologies, the malicious campaign leverages social media to distribute the malware and is reportedly tied to the current geopolitical climate in the region. “The attackers are hosting malware on legitimate online file-sharing accounts or Telegram channels that have been created specifically for this purpose.”

The campaign is said to have claimed over 900 victims since the fall of 2024, indicating that it is not particularly targeted. The majority of victims are located in Libya, Saudi Arabia, Egypt, Turkey, the United Arab Emirates, Qatar, and Tunisia.

See also: Phantom Goblin delivers stealer malware

The malicious activity is attributed to a group called Desert Dexter and was discovered in February 2025. It mainly involves creating temporary Facebook accounts and news feeds. These accounts are then used to post ads containing links to a file-sharing service or Telegram channel.

The links redirect users to a version of the AsyncRAT malware that has been modified to include an offline keylogger, search for 16 different crypto extensions and applications and communicate with a Telegram bot.

The kill chain begins with a RAR archive that contains either a batch script or a JavaScript file. These are programmed to execute a PowerShell script that is responsible for triggering the second stage of the attack.

See also: BadBox malware disrupted on 500,000 infected Android devices

It terminates processes related to various .NET services that could prevent the malware from starting, deletes files with the BAT, PS1, and VBS extensions from the “C:\ProgramData\WindowsHost” and “C:\Users\Public” folders, and creates a new VBS file in C:\ProgramData\WindowsHost and BAT and PS1 files in C:\Users\Public.

The script then establishes persistence on the system, collects and exports system information to a Telegram bot, takes screenshots, and finally launches the AsyncRAT payload by inserting it into the executable file “aspnet_compiler.exe”.

Further analysis of the messages sent to the Telegram bot revealed screenshots of the attacker’s own desktop called “DEXTERMSI”. Thus, the PowerShell script as well as a tool called Luminosity Link RAT. The Telegram bot also contains a link to a Telegram channel called “dexterlyly”, which suggests that the threat actor may be from Libya. The channel was created on October 5, 2024.

See also: New polyglot malware hits aviation and satellite communications companies

“The majority of victims are ordinary users, including workers in the following sectors: oil production, construction, information technology [and] agriculture,” the researchers said.

“The tools used by Desert Dexter are not particularly sophisticated, but the combination of Facebook ads with legitimate services and references to the geopolitical situation has led to the infection of many devices“.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

AsyncRAT malware Desert Dexter

Malware protection

The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.

Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.

You should also be careful with emails and messages you receive. Many RAT malware (AsyncRAT malware) are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS