AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
AsyncRAT can enumerate the NetBIOS name on targeted machines. |
| T1033 System Owner/User Discovery |
AsyncRAT can check if the current user of a compromised system is an administrator. |
| T1053.005 Scheduled Task |
AsyncRAT can create a scheduled task to maintain persistence on system start-up. |
| T1056.001 Keylogging |
AsyncRAT can capture keystrokes on the victim’s machine. |
| T1057 Process Discovery |
AsyncRAT can examine running processes to determine if a debugger is present. |
| T1059.003 Windows Command Shell |
AsyncRAT can be deployed via batch script. |
| T1090.003 Multi-hop Proxy |
|
| T1105 Ingress Tool Transfer |
AsyncRAT has the ability to download files including over SFTP. |
| T1106 Native API |
AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`. |
| T1113 Screen Capture |
AsyncRAT has the ability to view the screen on compromised hosts. |
| T1124 System Time Discovery |
AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration. |
| T1125 Video Capture |
AsyncRAT can record screen content on targeted systems. |
| T1204.002 Malicious File |
AsyncRAT has been executed through victims opening malicious file attachments. |
| T1497.001 System Checks |
AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments. |
| T1564.003 Hidden Window |
AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.