Skip to main content
AsyncRAT: Malvertising to Trojanized Installer operation cover
COMING SOONIntermediatePRO

AsyncRAT: Malvertising to Trojanized Installer

An IT admin searching for a remote management tool clicks a paid search advertisement and downloads what appears to be a legitimate installer. The ZIP contains an AutoIt-compiled fake setup executable that drops a PowerShell loader, which fetches AsyncRAT from a staging server. The RAT establishes persistence via a scheduled task and beacons to a C2 server. Correlate web proxy records, Windows event logs, XDR file and process artifacts, and firewall egress traffic to trace the full chain from malvertising lure to active command-and-control.

45m
7 tasks
50 points
Pro

Launches in 4 days

Aug 4, 2026

Tuesday, August 4, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

XDRSIEMFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Trace the sponsored result that started the chain
2Name the fake installer that ran on the endpoint
3Trace the loader chain through the process tree
4Identify how AsyncRAT survives a reboot
5Locate the AsyncRAT command-and-control server
6Map the persistence technique to MITRE ATT&CK
7Confirm the RAT binary with its hash

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 4, 2026, you can jump straight in.

Get Started Free