{"id":10489,"date":"2025-07-16T12:37:12","date_gmt":"2025-07-16T05:37:12","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10489"},"modified":"2026-02-05T12:37:18","modified_gmt":"2026-02-05T05:37:18","slug":"su-troi-day-cua-asyncrat-va-nhung-nhanh-ma-doc-mang-tinh-tuy-bien-cao","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/16\/su-troi-day-cua-asyncrat-va-nhung-nhanh-ma-doc-mang-tinh-tuy-bien-cao\/","title":{"rendered":"S\u1ef1 tr\u1ed7i d\u1eady c\u1ee7a AsyncRAT v\u00e0 nh\u1eefng nh\u00e1nh m\u00e3 \u0111\u1ed9c mang t\u00ednh t\u00f9y bi\u1ebfn cao"},"content":{"rendered":"<p><b>AsyncRAT, t\u1eebng l\u00e0 m\u1ed9t c\u00f4ng c\u1ee5 \u0111i\u1ec1u khi\u1ec3n t\u1eeb xa m\u00e3 ngu\u1ed3n m\u1edf \u0111\u01a1n gi\u1ea3n, nay \u0111\u00e3 bi\u1ebfn th\u00e0nh m\u1ed9t h\u1ec7 sinh th\u00e1i m\u00e3 \u0111\u1ed9c \u0111\u1ea7y ph\u1ee9c t\u1ea1p. N\u00f3 li\u00ean t\u1ee5c sinh s\u00f4i c\u00e1c bi\u1ebfn th\u1ec3 m\u1edbi v\u1edbi kh\u1ea3 n\u0103ng c\u1ea5y gh\u00e9p linh ho\u1ea1t, k\u1ef9 thu\u1eadt che gi\u1ea5u tinh vi v\u00e0 chi\u1ebfn thu\u1eadt n\u00e9 tr\u00e1nh ng\u00e0y c\u00e0ng kh\u00f3 \u0111\u1ed1i ph\u00f3. T\u1eeb m\u1ed9t d\u1ef1 \u00e1n tr\u00ean GitHub, AsyncRAT \u0111\u00e3 tr\u1edf th\u00e0nh n\u1ec1n t\u1ea3ng ph\u1ed5 bi\u1ebfn trong gi\u1edbi t\u1ed9i ph\u1ea1m m\u1ea1ng, mang theo c\u1ea3 s\u1ef1 s\u00e1ng t\u1ea1o l\u1eabn nguy hi\u1ec3m trong t\u1eebng d\u00f2ng m\u00e3.<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"AsyncRAT.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/asyncrat-png.17321\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"AsyncRAT.png\" src=\"https:\/\/whitehat.vn\/attachments\/asyncrat-png.17321\/\" alt=\"AsyncRAT.png\" width=\"700\" height=\"390\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<h3>T\u1eeb m\u00e3 ngu\u1ed3n m\u1edf \u0111\u1ebfn c\u00f4ng c\u1ee5 t\u1ea5n c\u00f4ng to\u00e0n n\u0103ng\u200b<\/h3>\n<p>AsyncRAT ra m\u1eaft tr\u00ean GitHub t\u1eeb n\u0103m 2019, vi\u1ebft b\u1eb1ng C# v\u00e0 h\u1ed7 tr\u1ee3 c\u00e1c ch\u1ee9c n\u0103ng nh\u01b0 keylogger, ch\u1ee5p m\u00e0n h\u00ecnh, \u0111\u00e1nh c\u1eafp th\u00f4ng tin x\u00e1c th\u1ef1c. D\u00f9 c\u00f3 nhi\u1ec1u \u0111i\u1ec3m t\u01b0\u01a1ng \u0111\u1ed3ng v\u1edbi Quasar RAT v\u1ec1 m\u1eb7t kh\u00e1i ni\u1ec7m, AsyncRAT \u0111\u01b0\u1ee3c vi\u1ebft l\u1ea1i ho\u00e0n to\u00e0n t\u1eeb \u0111\u1ea7u. M\u1ed9t \u0111i\u1ec3m \u0111\u00e1ng ch\u00fa \u00fd l\u00e0 \u0111o\u1ea1n m\u00e3 m\u00e3 h\u00f3a AES-256 v\u00e0 SHA-256 trong AsyncRAT \u0111\u01b0\u1ee3c sao ch\u00e9p t\u1eeb Quasar, cho th\u1ea5y c\u00e1c d\u1ef1 \u00e1n m\u00e3 \u0111\u1ed9c th\u01b0\u1eddng chia s\u1ebb v\u00e0 t\u00e1i s\u1eed d\u1ee5ng logic m\u00e3 h\u00f3a l\u1eabn nhau.<\/p>\n<p>Thi\u1ebft k\u1ebf m\u00f4-\u0111un v\u00e0 kh\u1ea3 n\u0103ng m\u1edf r\u1ed9ng cao gi\u00fap AsyncRAT nhanh ch\u00f3ng \u0111\u01b0\u1ee3c t\u1ed9i ph\u1ea1m m\u1ea1ng khai th\u00e1c, t\u1ea1o \u0111\u00e0 cho h\u00e0ng lo\u1ea1t fork m\u1edbi ra \u0111\u1eddi.<\/p>\n<h3>Nh\u1eefng bi\u1ebfn th\u1ec3 \u0111\u00e1ng g\u1eddm: DcRat v\u00e0 VenomRAT\u200b<\/h3>\n<p>Trong s\u1ed1 nhi\u1ec1u d\u1eabn xu\u1ea5t t\u1eeb AsyncRAT, hai bi\u1ebfn th\u1ec3 n\u1ed5i b\u1eadt l\u00e0 DcRat v\u00e0 VenomRAT.<\/p>\n<p>DcRat s\u1eed d\u1ee5ng th\u01b0 vi\u1ec7n MessagePack \u0111\u1ec3 c\u1ea3i thi\u1ec7n hi\u1ec7u n\u0103ng x\u1eed l\u00fd d\u1eef li\u1ec7u, \u0111\u1ed3ng th\u1eddi t\u00edch h\u1ee3p c\u00e1c k\u1ef9 thu\u1eadt n\u00e9 tr\u00e1nh ph\u00f2ng v\u1ec7 m\u1ea1nh m\u1ebd:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">V\u00f4 hi\u1ec7u h\u00f3a AMSI v\u00e0 ETW \u0111\u1ec3 v\u01b0\u1ee3t qua c\u01a1 ch\u1ebf gi\u00e1m s\u00e1t c\u1ee7a Windows<\/li>\n<li data-xf-list-type=\"ul\">T\u1ef1 \u0111\u1ed9ng k\u1ebft li\u1ec5u c\u00e1c ti\u1ebfn tr\u00ecnh b\u1ea3o m\u1eadt nh\u01b0 Taskmgr.exe, ProcessHacker.exe, MsMpEng.exe<\/li>\n<li data-xf-list-type=\"ul\">H\u1ec7 th\u1ed1ng plugin \u0111a d\u1ea1ng: t\u1eeb chi\u1ebfm quy\u1ec1n webcam, \u0111\u00e1nh c\u1eafp token Discord \u0111\u1ebfn m\u00e3 \u0111\u1ed9c t\u1ed1ng ti\u1ec1n d\u00f9ng AES-256<\/li>\n<\/ul>\n<p>VenomRAT c\u00f3 ki\u1ebfn tr\u00fac t\u01b0\u01a1ng t\u1ef1 DcRat nh\u01b0ng \u0111\u01b0\u1ee3c \u201cb\u01a1m\u201d th\u00eam t\u00ednh n\u0103ng v\u1edbi t\u1ed1c \u0111\u1ed9 ch\u00f3ng m\u1eb7t, tr\u1edf th\u00e0nh m\u1ed9t m\u1ed1i \u0111e d\u1ecda ri\u00eang bi\u1ec7t. B\u00ean c\u1ea1nh \u0111\u00f3, nh\u1eefng fork t\u01b0\u1edfng ch\u1eebng \u201ccho vui\u201d nh\u01b0 SantaRAT hay BoratRAT v\u1eabn xu\u1ea5t hi\u1ec7n trong chi\u1ebfn d\u1ecbch th\u1ef1c t\u1ebf, khi\u1ebfn vi\u1ec7c ph\u00e2n lo\u1ea1i tr\u1edf n\u00ean ph\u1ee9c t\u1ea1p h\u01a1n.<\/p>\n<h3>Plugin d\u1ecb bi\u1ec7t v\u00e0 k\u1ef9 thu\u1eadt che gi\u1ea5u s\u00e1ng t\u1ea1o\u200b<\/h3>\n<p>Vi\u1ec7c x\u00e1c \u0111\u1ecbnh bi\u1ebfn th\u1ec3 RAT th\u01b0\u1eddng d\u1ef1a v\u00e0o ph\u00e2n t\u00edch tr\u01b0\u1eddng Version trong t\u1eadp tin c\u1ea5u h\u00ecnh (th\u01b0\u1eddng \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a AES-256), th\u00f4ng s\u1ed1 Salt, ho\u1eb7c ch\u1ee9ng ch\u1ec9 X.509 nh\u00fang trong m\u00e3 ngu\u1ed3n. M\u1ed9t s\u1ed1 k\u1ef9 thu\u1eadt ti\u00ean ti\u1ebfn h\u01a1n s\u1eed d\u1ee5ng ph\u00e2n t\u00edch c\u1ea5u tr\u00fac m\u00e3, th\u0103m d\u00f2 C&amp;C ho\u1eb7c gi\u00e1m s\u00e1t h\u00e0nh vi th\u1ef1c thi.<\/p>\n<p>Nhi\u1ec1u plugin m\u1edbi xu\u1ea5t hi\u1ec7n v\u1edbi ch\u1ee9c n\u0103ng l\u1ea1 l\u00f9ng:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Screamer.dll: g\u00e2y ho\u1ea3ng lo\u1ea1n b\u1eb1ng h\u00ecnh \u1ea3nh v\u00e0 \u00e2m thanh<\/li>\n<li data-xf-list-type=\"ul\">WormUsb.dll: l\u00e2y lan qua USB b\u1eb1ng c\u00e1ch l\u00e2y nhi\u1ec5m file th\u1ef1c thi<\/li>\n<li data-xf-list-type=\"ul\">Brute.dll: brute-force th\u00f4ng tin SSH\/FTP<\/li>\n<li data-xf-list-type=\"ul\">cliper.dll: \u0111\u00e1nh c\u1eafp v\u00ed ti\u1ec1n m\u00e3 h\u00f3a b\u1eb1ng c\u00e1ch thay th\u1ebf \u0111\u1ecba ch\u1ec9 trong clipboard<\/li>\n<li data-xf-list-type=\"ul\">Signature Antivirus.dll: x\u00f3a c\u00e1c t\u1eadp tin c\u00f3 MD5 tr\u00f9ng v\u1edbi danh s\u00e1ch do k\u1ebb t\u1ea5n c\u00f4ng ch\u1ec9 \u0111\u1ecbnh<\/li>\n<\/ul>\n<p>M\u1ed9t s\u1ed1 bi\u1ebfn th\u1ec3 \u201cd\u1ecb bi\u1ec7t\u201d nh\u01b0 JasonRAT m\u00e3 h\u00f3a chu\u1ed7i b\u1eb1ng m\u00e3 Morse t\u00f9y bi\u1ebfn v\u00e0 s\u1eed d\u1ee5ng bi\u1ebfn v\u1edbi t\u00ean g\u1ecdi k\u1ef3 qu\u00e1i theo ch\u1ee7 \u0111\u1ec1 \u201csatan gi\u00e1o\u201d. Trong khi \u0111\u00f3, NonEuclid RAT t\u00edch h\u1ee3p plugin \u0111\u1ecbnh v\u1ecb \u0111\u1ecba l\u00fd, c\u00f2n XieBroRAT c\u00f3 th\u1ec3 \u0111\u00e1nh c\u1eafp th\u00f4ng tin tr\u00ecnh duy\u1ec7t v\u00e0 h\u1ed7 tr\u1ee3 Cobalt Strike.<\/p>\n<p>S\u1ef1 ti\u1ebfn h\u00f3a nhanh ch\u00f3ng c\u1ee7a h\u1ec7 sinh th\u00e1i AsyncRAT \u0111ang l\u00e0m m\u1edd ranh gi\u1edbi gi\u1eefa nh\u1eefng c\u00f4ng c\u1ee5 m\u00e3 \u0111\u1ed9c tinh vi v\u00e0 kh\u1ea3 n\u0103ng ti\u1ebfp c\u1eadn c\u1ee7a t\u1ed9i ph\u1ea1m m\u1ea1ng ph\u1ed5 th\u00f4ng. Nh\u1edd ki\u1ebfn tr\u00fac m\u00f4 \u0111un v\u00e0 kh\u1ea3 n\u0103ng t\u00f9y bi\u1ebfn d\u1ec5 d\u00e0ng, h\u00e0ng lo\u1ea1t bi\u1ebfn th\u1ec3 m\u1edbi li\u00ean t\u1ee5c ra \u0111\u1eddi v\u1edbi kh\u1ea3 n\u0103ng che gi\u1ea5u ng\u00e0y c\u00e0ng kh\u00e9o l\u00e9o c\u00f9ng c\u00e1c plugin mang t\u00ednh ph\u00e1 ho\u1ea1i cao. \u0110i\u1ec1u n\u00e0y khi\u1ebfn ho\u1ea1t \u0111\u1ed9ng ph\u00e1t hi\u1ec7n v\u00e0 ph\u00f2ng th\u1ee7 tr\u1edf n\u00ean kh\u00f3 kh\u0103n h\u01a1n bao gi\u1edd h\u1ebft.<\/p>\n<p>Tr\u01b0\u1edbc m\u1ed9t m\u00f4i tr\u01b0\u1eddng \u0111e d\u1ecda lu\u00f4n bi\u1ebfn \u0111\u1ed5i, gi\u1edbi chuy\u00ean gia an ninh m\u1ea1ng kh\u00f4ng th\u1ec3 ch\u1ec9 d\u1ef1a v\u00e0o c\u00e1c ch\u1ec9 d\u1ea5u t\u0129nh hay gi\u1ea3i ph\u00e1p ph\u00f2ng th\u1ee7 truy\u1ec1n th\u1ed1ng. Vi\u1ec7c theo d\u00f5i s\u00e1t sao h\u00e0nh vi m\u1edbi, ph\u00e2n t\u00edch m\u00e3 \u0111\u1ed9c ch\u1ee7 \u0111\u1ed9ng v\u00e0 \u00e1p d\u1ee5ng chi\u1ebfn l\u01b0\u1ee3c gi\u00e1m s\u00e1t linh ho\u1ea1t s\u1ebd l\u00e0 \u0111i\u1ec1u ki\u1ec7n s\u1ed1ng c\u00f2n \u0111\u1ec3 \u1ee9ng ph\u00f3 hi\u1ec7u qu\u1ea3 v\u1edbi l\u00e0n s\u00f3ng RAT th\u1ebf h\u1ec7 m\u1edbi. V\u00e0 v\u1edbi t\u1ed1c \u0111\u1ed9 ti\u1ebfn h\u00f3a nh\u01b0 hi\u1ec7n t\u1ea1i, \u0111\u00e2y c\u00f3 l\u1ebd ch\u1ec9 m\u1edbi l\u00e0 s\u1ef1 kh\u1edfi \u0111\u1ea7u.<\/p>\n<div style=\"text-align: right\"><b><i>Theo Cyber Press<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/su-troi-day-cua-asyncrat-va-nhung-nhanh-ma-doc-mang-tinh-tuy-bien-cao.18569\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/su-troi-day-cua-asyncrat-va-nhung-nhanh-ma-doc-mang-tinh-tuy-bien-cao.18569\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>AsyncRAT, t\u1eebng l\u00e0 m\u1ed9t c\u00f4ng c\u1ee5 \u0111i\u1ec1u khi\u1ec3n t\u1eeb xa m\u00e3 ngu\u1ed3n m\u1edf \u0111\u01a1n gi\u1ea3n, nay \u0111\u00e3 bi\u1ebfn th\u00e0nh m\u1ed9t h\u1ec7 sinh th\u00e1i m\u00e3 \u0111\u1ed9c \u0111\u1ea7y ph\u1ee9c t\u1ea1p. N\u00f3 li\u00ean t\u1ee5c sinh s\u00f4i c\u00e1c bi\u1ebfn th\u1ec3 m\u1edbi v\u1edbi kh\u1ea3 n\u0103ng c\u1ea5y gh\u00e9p linh ho\u1ea1t, k\u1ef9 thu\u1eadt che gi\u1ea5u tinh vi v\u00e0 chi\u1ebfn thu\u1eadt n\u00e9 tr\u00e1nh [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10489","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10489"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10489\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}