AsyncRAT Deployment via Phishing and Cloudflare Exploitation

AsyncRAT Deployment via Phishing and Cloudflare Exploitation

First seen 15 Jan 2026, 03:18 UTC Feeds.TrendmicroSocprimeScworld 82% similarity 31.3

Article Content

Browse articles
ThreatCluster

Threat actors have leveraged phishing emails to initiate a multi-stage intrusion chain that deploys the AsyncRAT remote access trojan. This operation utilizes Cloudflare's free-tier infrastructure and legitimate Python environments, employing Windows-native tools for execution and persistence. Victims are targeted through double-extension ZIP files leading to a WebDAV-hosted payload sequence.

ThreatCluster AI How this analysis works

Community

Browse all →