Campaign record
AsyncRAT and XWorm on one host
AsyncRAT and XWorm served from one shared host in fake CAPTCHA chains
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- 2025-05-19
- Indicators
- 1
- Sources
- 1
- Targets
- Windows
- Fake CAPTCHA verification
- AsyncRAT
- XWorm
Original research
- Trend Micro2025-05-19Vendor research
Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Pivoting through VirusTotal relationships from the fake-verification infrastructure, Trend Micro found a single host serving files that submissions had labelled as two different remote-access tools: AsyncRAT and XWorm. The delivery path ended in a video extension, matching the media-file naming used throughout the rest of the report. The same address had been reused over time to serve remote-access trojans and small downloaders, which the researchers read as one modular loader picking a payload to suit whatever machine it lands on. No specific lure page is tied to this host in the report; the connection is an infrastructure one, drawn from submission history and graph relationships rather than from an investigated incident.
Indicators
1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
| Indicator | Type | Role | Assessment | Report an error |
|---|---|---|---|---|
| ip, shown defanged for safety: 185 dot 7 dot 214 dot 108 | ip | Payload host | Not yet assessed | Report an error in ip record 62aeb6e4-ddd6-42ec-8943-f73e051e053f |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus, our own re-checks of these indicators or a recorded execution mechanism. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “AsyncRAT and XWorm on one host”, campaign ID 4d857e92, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/4d857e92/asyncrat-xworm-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.