Broadcom AsyncRAT and SideCopy Campaigns Target Users with Multi-Stage Attacks
Article Content
- •AsyncRAT uses a five-stage infection chain leveraging AutoIt for execution.
- •SideCopy exploits mshta.exe to deploy RATs via phishing emails.
- •Organizations must enhance monitoring and restrict execution of unsigned scripts.
Recent cybersecurity reports detail two significant malware campaigns involving AsyncRAT and SideCopy. The AsyncRAT campaign employs a five-stage infection chain utilizing a socially engineered batch file and the AutoIt interpreter, culminating in a .NET payload that steals information. Meanwhile, the SideCopy group exploits mshta.exe misuse to deploy RATs via phishing emails containing malicious ZIP files. Both campaigns leverage obfuscation techniques to evade detection and establish persistence on compromised systems. Organizations are advised to monitor for suspicious PowerShell and AutoIt activity, as well as to implement strict email security measures. The impact of these attacks could lead to significant data exfiltration and unauthorized access to sensitive information. Analysts recommend immediate isolation of affected endpoints and thorough memory forensics to mitigate damage.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…