1200KM / tool
AsyncRAT — Attack Tool
AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: AsyncRAT
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT-C-36 · G0099 · Pinned relationship source (relationship--bd8f6713-f3f2-4caf-b775-18e1062ce8bb)
- TA2541 · G1018 · Pinned relationship source (relationship--bc99bfb1-8529-4116-b702-07c37d333bcf)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1090.003 · Multi-hop Proxy · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1204.002 · Malicious File · Detection rules & anomalies
- T1497.001 · System Checks · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1568 · Dynamic Resolution · Detection rules & anomalies
- T1568.002 · Domain Generation Algorithms · Detection rules & anomalies
- T1622 · Debugger Evasion · Detection rules & anomalies
- T1680 · Local Storage Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Scheduled Job Creation · DC0001
- Scheduled Job Metadata · DC0005
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Authentication · DC0002
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.