Threat Advisory

Obfuscated JavaScript Droppers Deliver XWorm and AsyncRAT via Paste.ee Abuse

Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A malicious campaign has been identified that abuses the paste.ee service to deliver remote access trojans like XWorm and AsyncRAT. It began with a seemingly corrupted JavaScript file filled with random Unicode characters. After removing the obfuscation, the script was found to build HTTP requests to download malware from paste.ee. This technique allows attackers to avoid detection by hiding malicious payloads behind a trusted platform. The files are disguised with names like “DOCUMENT FOR DELIVERY INFORMATION.js” to trick users.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A malicious campaign has been identified that abuses the paste.ee service to deliver remote access trojans like XWorm and AsyncRAT. It began with a seemingly corrupted JavaScript file filled with random Unicode characters. After removing the obfuscation, the script was found to build HTTP requests to download malware from paste.ee. This technique allows attackers to avoid detection by hiding malicious payloads behind a trusted platform. The files are disguised with names like “DOCUMENT FOR DELIVERY INFORMATION.js” to trick users.[emaillocker id="1283"]

The JavaScript dropper uses Unicode junk to hide its true behavior. Once cleaned, it forms a URL pointing to paste.ee and uses ActiveX to download and run a payload. Thousands of such paste URLs were identified; many still live and serving Windows PE files. The downloaded executables included XWorm and AsyncRAT, capable of keylogging, screen capturing, and persistent access. AsyncRAT samples used AES-encrypted configs and connected to global C2 servers. These tools give attackers remote control, data theft capabilities, and stealth persistence on infected systems.

This campaign demonstrates how attackers exploit trusted services like paste.ee to evade security tools. The malware delivery method is lightweight, obfuscated, and easily overlooked. The supporting infrastructure spans various global networks, uses unusual ports, and specific SSL certificate patterns. Defenders should watch for unusual traffic to paste.ee, block suspicious URL patterns, and monitor known indicators of compromise linked to XWorm and AsyncRAT activity. This highlights the need for vigilance even when dealing with commonly trusted platforms.

THREAT PROFILE:

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Initial Access T1566.002 Phishing Spearphishing Link
Execution T1059.005 Command and Scripting Interpreter JavaScript
T1059.005
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defense Evasion T1027 Obfuscated Files or Information –
T1564.003 Hide Artifacts Hidden Files and Directories
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1056.001 Input Capture Keylogging
T1113 Screen Capture –
Command & Control T1071.001 Application Layer Protocol Web Protocols
T1095 Non-Application Layer Protocol –
Exfiltration T1041 Exfiltration Over C2 Channel –

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu