Malware Surge: AsyncRAT, Remcos, and Xworm Dominate Threat Landscape
Global malware activity has seen a significant surge, with remote access trojans (RATs) like AsyncRAT, Remcos, and Xworm leading the charge in recent threat sample uploads.

The past week has witnessed a sharp increase in global malware activity, with remote access trojans (RATs), information stealers, and loaders all showing substantial week-over-week gains. According to data from ANY.RUN, AsyncRAT emerged as the most prevalent threat with 211 uploads, closely followed by Remcos with 196 and Xworm with 183. This trend underscores the continued dominance of RAT-based intrusions as a primary tactic for cybercriminals seeking persistent access to compromised Windows systems.
AsyncRAT, a .NET-based remote access trojan, maintained its top position with a modest increase in uploads. Its delivery often involves phishing emails containing malicious attachments or links. Once installed, AsyncRAT grants attackers extensive control, including remote command execution, keylogging, screen capture, and data exfiltration. Notably, recent campaigns have seen AsyncRAT operators leveraging trusted cloud infrastructure, such as Cloudflare's free-tier services and TryCloudflare tunnels, to host their payload delivery servers, complicating detection by conventional security tools.
Remcos RAT experienced the most significant gain among the top three, rising by 59 samples to reach 196 uploads. This surge indicates an intensifying focus on espionage and surveillance-driven campaigns. Originally marketed as a legitimate remote administration tool, Remcos has evolved into a favored platform for cybercriminals and initial access brokers focused on espionage and credential theft. Newer variants have shifted towards real-time surveillance, capturing live webcam footage and transmitting keystrokes instantly, effectively transforming infected machines into live monitoring feeds for attackers.
Xworm, a highly adaptable and modular RAT sold through malware-as-a-service channels, followed closely with 183 uploads and a 16-sample increase. Recent Xworm campaigns have employed a variety of file formats and scripting languages, including PowerShell, VBS, and HTA, along with Office macro exploits like CVE-2018-0802, to evade endpoint defenses. Beyond standard RAT functionalities, newer Xworm builds also incorporate destructive capabilities, enabling the deployment of stealthy infostealer payloads, file encryption, and distributed denial-of-service (DDoS) features.
Other notable threats include AgentTesla, which ranked fourth with 172 uploads and a sharp 51-sample increase, reaffirming its status as a prolific credential-stealing Trojan. Stealc posted the largest weekly jump of the entire list, up 67 samples to 159 uploads, followed by Vidar at 157. Both are widely used information stealers designed to harvest browser credentials, cryptocurrency wallet data, and session tokens from infected endpoints.
DonutLoader, a growing delivery mechanism for secondary payloads, climbed 16 samples to 140 uploads, while Lumma Stealer rose 27 samples to 126. Formbook rounded out the mid-tier with 97 uploads, up 21. Snake was the only family among the top ten to decline, dropping two samples to 93, a notable exception amidst the broad surge.
Security teams are advised to prioritize detection rules for phishing-based delivery chains, monitor for anomalous PowerShell and HTA execution, and flag traffic to known command-and-control infrastructure associated with Remcos, AsyncRAT, and Xworm to mitigate the impact of this activity spike. The widespread adoption of these versatile RATs and info-stealers highlights the ongoing need for robust endpoint detection and response capabilities, coupled with vigilant user awareness training.