Skip to content
AsyncRAT and SideCopy Campaigns Target Users with Multi-Stage Attacks

AsyncRAT and SideCopy Campaigns Target Users with Multi-Stage Attacks

First seen 18 Sep 2026, 23:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 00:56 UTC
  • AsyncRAT uses a five-stage infection chain leveraging AutoIt for execution.
  • SideCopy exploits mshta.exe to deploy RATs via phishing emails.
  • Organizations must enhance monitoring and restrict execution of unsigned scripts.

Recent cybersecurity reports detail two significant malware campaigns involving AsyncRAT and SideCopy. The AsyncRAT campaign employs a five-stage infection chain utilizing a socially engineered batch file and the AutoIt interpreter, culminating in a .NET payload that steals information. Meanwhile, the SideCopy group exploits mshta.exe misuse to deploy RATs via phishing emails containing malicious ZIP files. Both campaigns leverage obfuscation techniques to evade detection and establish persistence on compromised systems. Organizations are advised to monitor for suspicious PowerShell and AutoIt activity, as well as to implement strict email security measures. The impact of these attacks could lead to significant data exfiltration and unauthorized access to sensitive information. Analysts recommend immediate isolation of affected endpoints and thorough memory forensics to mitigate damage.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
AsyncRAT infection chain identified
A five-stage AsyncRAT infection chain was discovered, utilizing AutoIt and obfuscation techniques to evade detection.
Socprime
2026-09-18
SideCopy attack chain documented
Trellix analysts reported on SideCopy's use of mshta.exe to deploy RATs through phishing emails with malicious ZIP files.
Broadcom

More articles in this cluster (2)

Following this threat?

Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed