$ techbeacon▋
Phishing

AsyncRAT Campaign Uses AutoIt and PowerShell to Embed Remote‑Access Trojan in Windows CharMap Process

AsyncRAT Campaign Uses AutoIt and PowerShell to Embed Remote‑Access Trojan in Windows CharMap Process

A multi‑stage malware operation identified as AsyncRAT is leveraging a chain of scripting tools to hide a .NET remote‑access trojan inside the legitimate Windows utility charmap.exe, security researchers reported.

The intrusion begins with a socially engineered batch file that appears to be a harmless document or utility. When executed, the batch script silently launches a PowerShell command that runs in the background, evading typical command‑prompt visibility. The PowerShell payload then downloads an AutoIt script, which is used to facilitate further obfuscation and to prepare the target process for injection.

Once the AutoIt component is active, it injects the .NET‑based AsyncRAT payload into the charmap.exe process, a core Windows application used for viewing character maps. By nesting the malicious code within a trusted system binary, the attackers aim to bypass conventional endpoint defenses that rely on whitelisting known executables.

Analysts describe the operation as a five‑stage campaign: initial lure, batch execution, concealed PowerShell activity, AutoIt abuse, and final process injection. Each step is designed to blend with normal system activity, making detection difficult for both users and automated security tools. The use of AutoIt, a scripting language often employed for legitimate automation, adds another layer of complexity because its binaries are commonly allowed on corporate networks.

AsyncRAT is a remote‑access trojan that provides attackers with capabilities such as file manipulation, credential harvesting, and command execution. Embedding it in charmap.exe not only helps it remain resident on infected machines but also reduces the likelihood of triggering alerts based on anomalous process behavior.

Security experts recommend that organizations monitor for unusual PowerShell command lines, unexpected AutoIt script executions, and the presence of unknown modules within system processes like charmap.exe. Updating endpoint protection signatures, enforcing strict execution policies for scripts, and employing behavior‑based detection can mitigate the risk posed by this and similar campaigns.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related