Date: 09/22/2026
Severity: High
Summary
AsyncRAT uses a multi-stage malware delivery mechanism in which the AutoIT component serves as the initial loader, while PowerShell facilitates execution of the subsequent stage. The final AsyncRAT payload provides attackers with remote access, including system information collection, command execution, Stealing, Screen Capture, and C2 communication. The AutoIT stage acts as an intermediary layer between the on-disk executable and the .NET payload loaded in memory, helping reduce the effectiveness of signature-based detection.
Indicators of Compromise (IOC) List
IP Address | 158.51.122.136 |
Hash | 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda
22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a
4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c
61056e4c274694ca2553e715c93dc2768def716de750598d99df79252bc4923d
ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("158.51.122.136") or srcipaddress IN ("158.51.122.136") |
Detection Query 2 : | sha256hash IN ("15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda","22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a","ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6","61056e4c274694ca2553e715c93dc2768def716de750598d99df79252bc4923d","4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c")
|
Reference:
https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/