Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
RAT

AsyncRAT

RAT 14 detections found

Also known as: Async RAT, Trojan.AsyncRAT, Backdoor.AsyncRAT, NYANxCAT

AsyncRAT is an open-source, C#-based remote access trojan originally published on GitHub (derived from the NYANxCAT project) that provides screen capture, keylogging, credential theft, and remote command execution over an encrypted C2 channel. Its public source code has spawned a large ecosystem of forks and commercial crypters (e.g., the 3LOSH crypter tracked by Cisco Talos), and it remains one of the most commonly delivered commodity RATs in phishing and malvertising campaigns. Recent incident-response reporting (Trend Micro, 2023) documents it being injected into legitimate Windows processes such as aspnet_compiler.exe to evade detection.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules