Hackers are using a commonly used Windows automation tool to conceal AsyncRAT, a remote-access trojan, within a trusted system process. This case underscores how attackers blend social engineering, built-in scripting, and trusted programs rather than relying on a single malicious file. This technique redirects suspicious network traffic and credential-access activities into a signed Windows process, a pattern also observed in process injection defense evasion cases that can frustrate checks focused solely on executable names.

Here are the IoCs: - **Filename / SHA-256 Right-click to open Invoice Details.bat** - **ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3 Initial socially engineered batch-file lure and reported hash** - **Filename / SHA-256 kojuyn.ini** - **4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a AutoIt loader script and reported hash** - **Filename / SHA-256 3200000.exe** - **22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e3 Recovered injected-stage executable and reported hash** - **Filename / SHA-256 3200000_02C37000.exe** - **15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671 Later recovered payload stage and reported hash** - **Filename / SHA-256 Veukuzmw.dll** - **61056e4c274694ca2553e715c93dc2768def716de750598d99df79252b Final AsyncRAT DLL payload and reported hash** - **Filename ogftogcyiblzjccmcbnw.exe** - **Renamed legitimate AutoIt interpreter used to launch the loader** - **Filename nloemfbihmhm** - **Extensionless encrypted payload read and decrypted by the AutoIt loader** - **Filename h73la8.bat** - **Startup-folder persistence batch file** - **C2 IP address and port 158[.]51[.]122[. ]136:4944** - **AsyncRAT command-and-control endpoint observed in the analysis** - **Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.