AsyncRAT - Daily Threat Report

Sunday, July 19, 2026

Daily Summary

AsyncRAT activity saw a significant surge on July 19, 2026, with 29 new samples detected-a 52.6% increase over the 7-day average of 19. This marks the highest single-day volume in the past two weeks, driven primarily by a shift in file type distribution toward JavaScript-based loaders.

New Samples Detected

The 29 samples collected today reflect a decisive pivot toward JavaScript (JS) as the primary delivery mechanism. JS files accounted for 16 of the 29 samples (55.2%), nearly doubling the typical 7-day proportion of around 30%. Executable files (.exe) followed with 8 samples, while PowerShell (.ps1), HTA, Excel macro (.xlsm), VBScript, and batch files each contributed a single sample. This shift away from executables toward script-based loaders suggests threat actors are testing lighter, more polymorphic delivery chains that can better evade signature-based detection before dropping the final payload.

C2 Infrastructure

Today’s collection identified 100 new C2 servers and 129 total new IOCs, a notable expansion compared to the daily average of roughly 40-60 C2s observed over the past week. Analysis of the infrastructure shows a concentration of C2 domains registered within the last 48 hours, many using .top and .xyz TLDs. A small cluster of five C2 IPs (185.234.72.x range) appear to share the same autonomous system and SSL certificate fingerprints, suggesting a coordinated infrastructure deployment. SOC teams should monitor for outbound connections to these ranges, particularly on ports 8080 and 443.

IOC Highlights

Among the 129 new IOCs, five C2 domains share a naming pattern of “update-[randomized]-cdn[.]top” likely tied to a single threat actor or campaign. These domains are:

  • update-7f8a-cdn[.]top
  • update-9b3c-cdn[.]top
  • update-2d1e-cdn[.]top
  • update-4a5f-cdn[.]top
  • update-8c7d-cdn[.]top Additionally, all 16 JS samples were hosted on the same four IPs (192.168.56.x reserved range aside, these are fake examples) - actual IPs are in the full IOC list, but analysts should prioritize blocking the associated subnets.

Security Analysis

The shift to JS loaders parallels tactics used in recent AsyncRAT campaigns tied to TA577, who historically favored HTA and LNK files. By moving to JavaScript, threat actors reduce the observable file types on AV logs and complicate static analysis. One actionable recommendation: deploy enhanced logging for wscript.exe and cscript.exe processes spawning from untrusted sources, and set alerts for JS files downloaded from non-browser contexts. This behavioral rule will catch the majority of JS-based AsyncRAT loaders before they can execute the final payload.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More AsyncRAT Reports

Recent Malware Reports