The study reconstructs the evolution of AsyncRAT and its derivatives, highlighting differences and uses. Some variants are enhanced, others created for fun but still dangerous. The open source code facilitates its diffusion even among inexperienced actors
ESET, a global European leader in the cybersecurity market, has published a detailed analysis on AsyncRAT, a remote access tool designed to monitor and control devices remotely. Over the years, AsyncRAT has established itself as one of the fundamental tools of modern malware, evolving into a widespread threat and giving rise to a branching network of variants and forks, i.e. customized and improved versions of the original. The published analysis offers an overview of the most relevant forks, highlighting their evolution and the relationships between the different versions.
AsyncRAT, an open source RAT, was released on GitHub in 2019 by a user known by the nickname NYAN CAT. It integrates a wide range of typical RAT features, such as keylogging, screen capture, credential theft and more. Its simplicity and the fact that it is open source have made it a highly appreciated tool in cybercriminal contexts, with extensive use in numerous attacks.
"AsyncRAT has introduced significant improvements, particularly in modular architecture and advanced evasion features, which make it more adaptable and difficult to detect in modern threat intelligence environments. The plug-in-based structure and ease of modification have favored the proliferation of numerous forks, significantly expanding the possibilities for malware customization," explains Nikola Knežević, ESET researcher and author of the research.
Since its release, AsyncRAT has spawned a multitude of forks that have expanded its functionality. Some versions have evolved, adding new features and refinements; others, however, present minimal changes compared to the original. According to telemetry data collected by ESET, the variants most used in attacks are DcRat, VenomRAT and SilverRAT.
DcRat represents an evolution compared to AsyncRAT in terms of functionality and operational capabilities, while VenomRAT introduces further advanced tools. However, not all AsyncRAT variants were created with "serious" intentions: there are also forks created with a playful intent, such as SantaRAT or BoratRAT. Despite originating as provocative versions, ESET has detected cases where they have been used in real attacks. ESET Research's analysis also examines some lesser-known forks which, despite representing less than 1% of the samples detected, introduce advanced features compared to the basic version. These are often isolated developments, created by individual users or small groups.
"The availability of frameworks like AsyncRAT drastically lowers the access threshold for those entering cybercrime, allowing even inexperienced individuals to launch sophisticated attacks with minimal effort. This phenomenon contributes to the acceleration in the development and customization of malicious tools. To counter this evolution, it is essential to adopt proactive detection strategies and in-depth behavioral analyses", concludes Knežević.






