AsyncRAT - Daily Threat Report

Sunday, September 13, 2026

By Yazoul AI · automated

Daily Summary

AsyncRAT activity reached 67 new samples on 2026-09-13, a 146% increase over the 7-day average of 27. This is the largest single-day volume in the tracking window and coincides with 100 new C2 servers and 167 new IOCs, all recorded in a single reporting cycle. The combination of high sample volume and fresh C2 infrastructure suggests an active distribution push rather than routine background noise.

New Samples Detected

The file type breakdown is dominated by .exe (48 samples, 72%), but the script-based loaders remain significant: 11 .js, 4 .vbs, 1 .vbe, and 1 .ps1. This mix is consistent with AsyncRAT’s established pattern of pairing a compiled payload with a script stager, but the .exe share is higher than typical for staged campaigns. The single .dll and single .bin are likely loader components or staged shellcode rather than standalone artifacts, and are worth flagging for sandbox correlation.

C2 Infrastructure

The 100 new C2 servers registered today is the standout figure. That is more than three times the 7-day average sample count and suggests either a bulk registration event or a C2 rotation across a large botnet. AsyncRAT operators frequently use dynamic DNS and cheap VPS providers, so a cluster of this size likely reflects a coordinated infrastructure refresh rather than 100 independent actors. Analysts should prioritize clustering these servers by ASN and registration timestamp to identify shared operator fingerprints.

7-Day Trend

Today’s 67 samples are 146% above the 7-day average of 27, well past the 25% deviation threshold. This is not a marginal uptick. The prior six days evidently ran near or below the 27 average, meaning today represents a step change. Combined with the C2 surge, the most likely explanation is a new campaign launch or a re-activation of an existing distribution channel.

IOC Highlights

167 new IOCs in one day warrants attention. The ratio of C2 servers (100) to total IOCs (167) leaves roughly 67 non-C2 indicators, presumably payload hashes, loader URLs, or registry artifacts. Security teams should ingest these promptly but expect overlap with existing AsyncRAT signatures, given the malware’s stable core.

Security Analysis

The scale of C2 registration relative to sample volume is the non-obvious signal here. Typical AsyncRAT pushes see C2 and sample counts roughly track each other; today’s 100-to-67 ratio implies infrastructure was stood up ahead of the payload wave, which is characteristic of a staged campaign preparing for broader distribution rather than reacting to takedowns. This mirrors the pattern seen in the 2024 AsyncRAT malspam clusters that pre-registered domains before phishing waves. Actionable recommendation: block or sinkhole the new C2 set at the DNS and proxy layer now, before the corresponding phishing or drive-by delivery wave lands, and monitor for .js and .vbs loaders calling those domains in the next 48 to 72 hours.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More AsyncRAT Reports

Recent Malware Reports