AsyncRAT

S1087

Tool.View on attack.mitre.org

About this tool

AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1016
System Network Configuration Discovery

AsyncRAT can enumerate the NetBIOS name on targeted machines.

T1033
System Owner/User Discovery

AsyncRAT can check if the current user of a compromised system is an administrator.

T1053.005
Scheduled Task

AsyncRAT can create a scheduled task to maintain persistence on system start-up.

T1056.001
Keylogging

AsyncRAT can capture keystrokes on the victim’s machine.

T1057
Process Discovery

AsyncRAT can examine running processes to determine if a debugger is present.

T1059.003
Windows Command Shell

AsyncRAT can be deployed via batch script.

T1090.003
Multi-hop Proxy

AsyncRAT can proxy C2 through a Tor client.

T1105
Ingress Tool Transfer

AsyncRAT has the ability to download files including over SFTP.

T1106
Native API

AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`.

T1113
Screen Capture

AsyncRAT has the ability to view the screen on compromised hosts.

T1124
System Time Discovery

AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration.

T1125
Video Capture

AsyncRAT can record screen content on targeted systems.

T1204.002
Malicious File

AsyncRAT has been executed through victims opening malicious file attachments.

T1497.001
System Checks

AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments.

T1564.003
Hidden Window

AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`.

View all 20 procedure examples

Groups that use it2

Campaigns1

References3

  1. Cisco Operation Layover September 2021 Open source
    Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.
  2. Morphisec Snip3 May 2021 Open source
    Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.
  3. Telefonica Snip3 December 2021 Open source
    Jornet, A. (2021, December 23). Snip3, an investigation into malware. Retrieved September 19, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.