Analyzing AsyncRAT's Code Injection into Aspnet_Compiler.exe Across Multiple Incident Response Cases
released on 2023-12-13 @ 05:10:16 PM
This blog entry shows how AsyncRAT, a remote access trojan with features such as unauthorized access, keylogging, remote desktop control, and covert file manipulation, is a versatile tool for various threats, including ransomware.
The strategic use of multiple obfuscated scripts incorporating "living off the land" techniques grants malicious actors flexibility, enabling them to evade detection. Coupled with code injection into legitimate files like aspnet_compiler.exe, this technique significantly increases the challenge of detecting these threats.