A phishing campaign since early 2024 leverages legitimate cloud services like TryCloudflare to deliver evasive malware such as AsyncRAT, enabling remote access, credential theft, and ransomware across thousands of organizations. The campaign uses multi-stage execution with Python scripts and cloud tunneling to bypass traditional endpoint protections, highlighting the need for layered defense strategies. #AsyncRAT #TryCloudflare #Halcyon
Keypoints
- The campaign targets thousands of global organizations across multiple sectors without preference since early 2024.
- Threat actors deliver malware like AsyncRAT, XWorm, VenomRAT, and Remcos using phishing combined with legitimate cloud infrastructure abuse.
- Use of TryCloudflare tunnels and obfuscated Python scripts enables evasion of traditional endpoint protection and delays detection.
- The campaign likely originates from a new or rebranded cybercriminal group focused on scalable financial crime and potentially facilitating ransomware deployment.
- Mitigation strategies include blocking TryCloudflare tunnels, advanced email filtering and sandboxing, monitoring Python execution, deploying EDR and dedicated anti-ransomware solutions like Halcyon.
- The multi-stage attack chain involves phishing lures linking to Dropbox-hosted ZIP files, execution of shortcut (.URL, .LNK) files, batch scripts, and Python loaders to deploy RATs.
- Indicators of compromise include specific TryCloudflare subdomains and file hashes related to Python scripts, shellcode, and malware payloads identified by Halcyon.
MITRE Techniques
- [T1566] Phishing – The campaign begins with phishing lures linking to Dropbox-hosted ZIP files to initiate infection (“phishing lure that links to a Dropbox-hosted ZIP file”).
- [T1071] Application Layer Protocol – Use of TryCloudflare tunnels to download payloads through trusted cloud infrastructure for evasion (“using Cloudflare’s temporary tunnels to serve payloads from seemingly legitimate infrastructure”).
- [T1059] Command and Scripting Interpreter – Execution of obfuscated batch scripts and Python scripts to deploy malware (“execution of a heavily obfuscated batch script; and retrieval and execution of Python scripts”).
- [T1086] PowerShell – Behavioral detection of malicious scripting activity such as via Python or PowerShell is recommended (“flag anomalous use of scripting engines like PowerShell, Python, and Windows Script Host”).
- [T1041] Exfiltration Over C2 Channel – The RATs deployed enable data exfiltration via command and control mechanisms (“allow threat actors to remotely control an infected network across the full attack lifecycle, from initial access to data exfiltration”).
- [T1027] Obfuscated Files or Information – Use of obfuscated batch scripts and Python code to hinder analysis (“heavily obfuscated batch script,” “Python scripts that are used to deploy AsyncRAT”).
Indicators of Compromise
- [Domains] TryCloudflare Tunnel subdomains used for delivery – now-refer-several-tariff.trycloudflare.com, wizard-individual-intervals-franklin.trycloudflare.com
- [File Hashes] Malicious script and shellcode hashes detected – WSF: b16d2800811e7a72c90bea50640330966cdb931a03f76338478da682ea6fded7, LNK: 3d3a6d7905ca1387f3ec7a637cb672d6b6efa0f8efdbf819f756a8e5f92bc960, along with multiple Python and shellcode hashes for AsyncRAT, PureHVNC, and XWorm.
Read more: https://www.halcyon.ai/blog/asyncrat-campaign-continues-to-evade-endpoint-detection