AsyncRAT Deployment via Phishing and Cloudflare Exploitation
First seen 15 Jan 2026, 03:18 UTC
•

•82% similarity
•31.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Threat actors have leveraged phishing emails to initiate a multi-stage intrusion chain that deploys the AsyncRAT remote access trojan. This operation utilizes Cloudflare's free-tier infrastructure and legitimate Python environments, employing Windows-native tools for execution and persistence. Victims are targeted through double-extension ZIP files leading to a WebDAV-hosted payload sequence.
ThreatCluster AI
How this analysis works