Back to Feed
MalwareApr 14, 2026

@sicehice #AsyncRAT šŸ“” AsyncRAT botnet C2s: 81.163.111.127:9001 šŸ‡·šŸ‡ŗ 91.242.179.62:8808 šŸ‡·šŸ‡ŗ 91....

AsyncRAT botnet C2 servers identified across Russian IP infrastructure.

Summary

Security researcher @sicehice has identified four command-and-control (C2) servers associated with the AsyncRAT botnet, all hosted on Russian IP addresses. The IOCs include IP:port combinations across the 81.163.111.127 and 91.242.179.x ranges. This disclosure provides actionable intelligence for detection and blocking of AsyncRAT infrastructure.

Indicators of Compromise

  • ip — 81.163.111.127
  • ip — 91.242.179.62
  • ip — 91.242.179.84
  • malware — AsyncRAT