Netskope Threat Labs

AsyncRAT

ATP Sandbox Adv. HeuristicsAV

AsyncRAT is an open source remote administration tool that appeared on GitHub in 2019 and gives users encrypted remote control of Windows computers. Its module system supports keylogging, file transfer, remote desktop viewing, and payload downloads, and its free availability has made it one of the most abused RAT families. Cyberattackers deliver it through phishing emails, cracked software, and loaders, and they rely on its encrypted channels to blend command and control traffic into normal HTTPS.

First seen
March 2022
Last seen
October 2026
AsyncRatAsyncrat

20 techniques across 6 tactics.

TA0001 Initial Access

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1124System Time Discovery
  • T1680Local Storage Discovery

TA0009 Collection

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Backdoor.Asyncrat
ByteCode-MSIL.Backdoor.AsyncRat
ByteCode-MSIL.Backdoor.AsyncRAT
ByteCode-MSIL.Downloader.AsyncRat
ByteCode-MSIL.Downloader.AsyncRAT
ByteCode-MSIL.Dropper.AsyncRAT
ByteCode-MSIL.Spyware.AsyncRAT
ByteCode-MSIL.Trojan.AsyncRAT
Document-PDF.Trojan.AsyncRAT
Document-Word.Downloader.AsyncRAT