Daily Summary
AsyncRAT activity dropped sharply on 2026-09-20, with 12 new samples against a 7-day average of 34, a 64% decline. The drop is broad-based rather than a single-family outage, but C2 infrastructure tells the opposite story: 99 new servers and 111 new IOCs appeared today even as sample volume fell. That divergence suggests operators are staging infrastructure ahead of a relaunch or retooling cycle.
New Samples Detected
File type distribution shifted toward script-based delivery: 7 of 12 samples were .js, with 3 .exe and 2 .bat. The script-heavy mix is consistent with downloader chains that pull the AsyncRAT payload at runtime rather than shipping a standalone binary. With only 12 samples, naming patterns aren’t statistically meaningful, so I’d treat the script skew as the more useful signal.
C2 Infrastructure
The 99 new C2 servers against just 12 samples is the day’s real story. That ratio (roughly 8 new C2 endpoints per sample) is well above what we’d expect from normal operation, where samples and infrastructure scale together. Two explanations fit: either operators are rotating infrastructure to stay ahead of takedowns, or a larger-than-visible sample set exists behind the 12 we captured. The 111 new IOCs likely include domain and IP pairs tied to those servers.
7-Day Trend
At 12 samples, today sits 64% below the 7-day average of 34 - a deviation large enough to flag. One quiet day isn’t a trend reversal, but combined with the infrastructure surge, it’s worth watching whether sample volume rebounds over the next 48 hours.
IOC Highlights
With 111 new IOCs and 99 new C2 servers, defenders should prioritize ingestion today. The volume of fresh infrastructure suggests blocklist churn is high, and stale entries will age out quickly.
Security Analysis
The mismatch between low sample count and high C2 count is the non-obvious signal. In prior AsyncRAT campaigns, infrastructure buildouts have preceded sample surges by days, not followed them - operators stand up C2 before distributing payloads. That pattern argues against reading today as a genuine lull. A practical defensive step: rather than waiting for the sample surge, proactively block or sinkhole the 99 new C2 endpoints now, and monitor DNS logs for resolution attempts against them. Catching beaconing to staged infrastructure can surface infected hosts before the next distribution wave.