Top Tweets for #ASyncRAT
AI hype is now part of the lure. 📢 🤖
@TheHackerNews featured #FortiGuardLabs research on a campaign using fake AI-themed documents to deliver #AsyncRAT through a stealthy, multi-stage attack chain.
The files look like learning resources.
The payload gives attackers remote access.
🔗 Read the findings: https://t.co/WSEXWEGUrI

⚠️ Credential-focused malware remained highly active last week. #Vidar and #Stealc continued to grow, while #AsyncRAT maintained its lead and newer families like #SilentNet and #DonutLoader gained momentum.
📌 Trend to watch: attackers aren't relying on a single access path. Growth across stealers, RATs, and loaders suggests multiple stages of the intrusion chain are being scaled at the same time. For SOC teams, that increases the need to connect isolated signals before they become incidents.
Monitor the malware families driving today’s attacks: https://t.co/BB31YBdBW5
#Top10Malware

FortiGuard Labs uncovered AsyncRAT AI lures using fake AI guides and an AutoHotkey loader to inject a stealthy .NET RAT into memory.
#AsyncRAT #Malware #AIThreats #Cybersecurity #FortiGuard
https://t.co/utW6JgftpM

⚠️ Growth wasn't limited to a single family last week, with #XWorm, #Vidar, #Remcos, #Quasar, and #AgentTesla all on the rise, while #AsyncRAT declined from its previous peak.
📌 Trend to watch: when activity is spread across multiple malware families, attackers have more ways to reach the same objective. For SOC teams, that means focusing on common attack patterns and behaviors becomes more important than tracking individual malware.
Monitor the malware families driving today’s attacks: https://t.co/h6jDuc7jgm
#Top10Malware

Watch out as new findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.
Read: https://t.co/H4MQEcruPd
#Cybersecurity #Malware #AsyncRAT #Windows #AI #ClaudeCode
4483c987a478c51831b3ca263f465b0a
fly88[.]pro:80 & 443
#AsyncRAT
⚠️ Remote access malware remained resilient despite broader declines. #AsyncRAT continued to grow and #Remcos rebounded, while most other major families trended downward.
📌 Trend to watch: when fewer families account for a larger share of activity, defenders can miss the signal by focusing on overall volume alone. Concentrated campaigns often create repeated exposure to the same attack paths, increasing the likelihood of successful compromise.
Expand threat visibility in your SOC: https://t.co/TKjc0H22hQ
#Top10Malware

⚠️ Stealer activity surged last week. #Vidar, #Stealc, and #SalatStealer all increased, while #AsyncRAT and #DCRat also continued to grow.
📌 Trend to watch: credential theft is gaining momentum alongside remote access malware, giving attackers more opportunities to move from initial compromise to persistent access. For SOC teams, that means validating credential-related alerts quickly becomes even more important.
Expand threat visibility in your SOC: https://t.co/HrL13grF80
#Top10Malware

'Project Details Including Salary and Terms and Conditions 2026.lnk' seen from Australia @abuse_ch
https://t.co/2ywHgkrJ6H
Next stage:
hxxps://raw.githubusercontent(.)com/tiiisiet65-sudo/LoioioNoaisK/main/Download-macOSx.cmd (@osint_barbie)

51e389b6ae188838ab2dca3c3c23e75d
a322ba2cba0a11a58e20f0d4444e5932
clipviet[.]blog:6606
clipviet[.]blog:7707
clipviet[.]blog:8808
nangcucz[.]blog:443
nangcucz[.]blog:80
#AsyncRAT
bruma[.]com[.]co
172[.]67[.]182[.]189:8848
172[.]67[.]182[.]189:8080
172[.]67[.]182[.]189:443
104[.]21[.]18[.]163:8848
#AsyncRAT
![skocherhan's tweet photo. bruma[.]com[.]co
172[.]67[.]182[.]189:8848
172[.]67[.]182[.]189:8080
172[.]67[.]182[.]189:443
104[.]21[.]18[.]163:8848
#AsyncRAT https://t.co/uNwmeAfWZ3](https://pbs.twimg.com/media/HJFVvZfXgAALrml.jpg)
0e4473bf9200562aa0a4a1e38fa9f2b7
utn[.]uk[.]com
104[.]21[.]69[.]43:8443
104[.]21[.]69[.]43:25
104[.]21[.]69[.]43:20
104[.]21[.]69[.]43:80
104[.]21[.]69[.]43:3306
104[.]21[.]69[.]43:8080
172[.]67[.]204[.]83:20
#AsyncRAT
![skocherhan's tweet photo. 0e4473bf9200562aa0a4a1e38fa9f2b7
utn[.]uk[.]com
104[.]21[.]69[.]43:8443
104[.]21[.]69[.]43:25
104[.]21[.]69[.]43:20
104[.]21[.]69[.]43:80
104[.]21[.]69[.]43:3306
104[.]21[.]69[.]43:8080
172[.]67[.]204[.]83:20
#AsyncRAT https://t.co/jnNXJkK6as](https://pbs.twimg.com/media/HJERP9mWwAAY4w_.png)
sv368[.]us[.]com:6606
sv368[.]us[.]com:7707
sv368[.]us[.]com:8808
sv368[.]us[.]com:80
sv368[.]us[.]com:443
#ANARCHYRAT #AsyncRAT
![skocherhan's tweet photo. sv368[.]us[.]com:6606
sv368[.]us[.]com:7707
sv368[.]us[.]com:8808
sv368[.]us[.]com:80
sv368[.]us[.]com:443
#ANARCHYRAT #AsyncRAT https://t.co/bhSL7GUuUE](https://pbs.twimg.com/media/HI9MGR7WEAArK-z.jpg)
⚠️ Overall RAT activity cooled down last week, with #AsyncRAT, #XWorm, and #Remcos all declining, while stealers like #Vidar and #Stealc continued to grow.
📌 Trend to watch: this points to a shift toward credential access and large-scale delivery activity. For defenders, that usually means higher alert volume, broader exposure, and more pressure on early-stage triage.
Expand threat visibility in your SOC: https://t.co/eNP9eivvNt
#Top10Malware

LinkedIn Search leads to #CastleLoader delivering #AsyncRAT. Attackers use Clickfix lures with fake verification popups to mask PowerShell activity. The loader decrypts the payload via RC4, using the first 64 bytes as a key to bypass filters. Details: https://t.co/0t5xZQFNgk

Last Seen Hashtags on Sotwe
alaşehirpasif
Seen from Turkey
polki_69
EnemiesWithBenefits
Seen from Germany
boynuzlukoca
Seen from Turkey
thundr
Seen from India
sexo
Seen from United States
NoLimit #NoLimit #momson
Seen from Philippines
Nolimit ()
Seen from France
nolimit teenage filter:native_video since:2026-06-6
Seen from United States
ensest
Seen from Turkey
Most Popular Users

Elon Musk 
@elonmusk
240.6M followers

Barack Obama 
@barackobama
119.2M followers

Donald J. Trump 
@realdonaldtrump
111.7M followers

Cristiano Ronaldo 
@cristiano
110.5M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.6M followers

NASA 
@nasa
92.2M followers

Justin Bieber 
@justinbieber
90.9M followers

KATY PERRY 
@katyperry
87.6M followers

Taylor Swift 
@taylorswift13
81.4M followers

Lady Gaga 
@ladygaga
73M followers

Virat Kohli 
@imvkohli
69.8M followers

Kim Kardashian 
@kimkardashian
69.8M followers

YouTube 
@youtube
68.7M followers

Bill Gates 
@billgates
63.8M followers

Neymar Jr 
@neymarjr
62.5M followers

The Ellen Show
@theellenshow
62.4M followers

CNN 
@cnn
61.9M followers

X 
@x
60.8M followers

Selena Gomez 
@selenagomez
60.7M followers








![skocherhan's tweet photo. loeop[.]online
loeop[.]com
51[.]79[.]253[.]174:56001
AS16276 OVH SAS 🇸🇬
#AsyncRAT @smica83 https://t.co/Zi0yFWTIR8](https://pbs.twimg.com/media/HJlwm2cXoAAVcqC.jpg)



![skocherhan's tweet photo. 6cbf8c7edde85b3d1bacc907b67eb40f
ck44jili[.]com
104[.]21[.]93[.]147:6606
104[.]21[.]93[.]147:7707
104[.]21[.]93[.]147:8808
#AsyncRAT @abuse_ch https://t.co/DbhrCCLIWD](https://pbs.twimg.com/media/HIefiaTWcAA1166.jpg)




