fujeigroup.com: a server handing out picture files that hide AsyncRAT, and what to do if a loader fetched them
fujeigroup.com is a web address that URLhaus lists seven times in one week for picture files (img_*.png on port 8888) tagged stego, and four of them tagged AsyncRAT, a remote access trojan for Windows. A picture like that is not a virus you open by looking at it; it is the second stage that a loader already running on a PC fetches.
If you only saw the name in a log, nothing is proven. If something on your PC may have fetched these files, treat the PC as watched: change your passwords from another device, then scan and clean or reset Windows.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with a script, loader or program that downloads picture files from fujeigroup.com.
Do it yourself · free Remove fujeigroup.com (AsyncRAT, stego PNG files) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Fujeigroup.com (AsyncRAT, stego PNG files): summary
| Type | A malware server: URLhaus tags its picture files stego, and four of them AsyncRAT and rat (a remote access trojan for Windows) |
|---|---|
| Risk | High if a loader on your PC fetched its files: keystrokes, passwords, screen, camera and files may be seen or taken. Low if you only saw the name |
| Symptoms | Often none. Unknown scheduled tasks or Run key entries, and trusted programs such as RegSvcs.exe running with no reason, are the signs in the reports |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure |
| Our check (6 October 2026) | One visit to the secure home page: TLS error, no page. A broken home page clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 20 October 2025; first picture files reported 30 September 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No Microsoft detection name is known for the files on this server, because we did not open them. For AsyncRAT builds in general Microsoft uses Backdoor:MSIL/AsyncRAT!MTB |
| Name | Fujeigroup.com |
| Domain registered | 20 October 2025 |
| Evidence | 7 write-ups by security sites; details still limited |
| First seen | 30 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 6 October 2026 |
Facts checked on 6 October 2026 against the URLhaus data for fujeigroup.com held in our database (the abuse.ch host page itself only showed a verification screen to our tool), RDAP, one browser visit of our own, and published reports by Microsoft, MITRE ATT&CK, Splunk, Seqrite, LevelBlue SpiderLabs and the FTC.
We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and entry and were not tried on a live infection.
What fujeigroup.com is, and what we know about it
fujeigroup.com is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists as a place where malware was served, hidden inside PNG picture files. We found no public write-up of this one address, so what follows is what URLhaus shows, what we saw ourselves, and what security vendors have published about the technique and the malware family it is tagged with.
- 1
What URLhaus lists
Seven file addresses on fujeigroup.com, all on port 8888 in a folder called web, and all named img_ followed by six digits with the ending .png. They were added in three groups: four on 30 September 2026, two on 5 October and one on 6 October. All seven are marked online, all carry the threat label malware_download, and the reporter is abuse_ch.
- 2
What the tags mean
stego is short for steganography: data hidden inside another file, here inside a picture. AsyncRAT is the name of a remote access trojan, a program that lets a stranger control a computer. rat means the same thing. opendir means the folder could be listed by anyone who asked the server, which is why the first four files were found together. Four of the seven files are tagged AsyncRAT; the other three are tagged only stego.
- 3
What we could not confirm
We did not download any of the pictures, so we cannot tell you what is inside them, which AsyncRAT build they carry or where it reports to. URLhaus shows the tags, not a proof. We also do not know which program or message makes a victim's PC ask for these files. That first step is not visible from the server side.
- 4
What this means for you
If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a PC where something already ran and went to fetch one of these pictures. Pictures of this kind are not meant for people to view; a normal visitor has no reason to ask for them.
- Kind of threat
- A server that hands out PNG files tagged stego; four are tagged AsyncRAT, a remote access trojan for Windows
- Where the files are
- hxxp://fujeigroup[.]com:8888/web/img_NNNNNN.png: plain http on port 8888, not the usual web ports
- Domain registered
- 20 October 2025, expires 20 October 2026, registrar NameCheap, Inc.; the record was last changed on 16 August 2026 (RDAP, read 6 October 2026)
- URLhaus entries
- 7 file addresses, added 30 September, 5 October and 6 October 2026; all 7 online when we read our copy of the data
- Delivery trick
- Steganography: code hidden in picture files so a download looks like an image. The entry step on the victim's PC is not known
- Platform
- Windows. Microsoft describes AsyncRAT as a .NET program for Windows. Nothing we read says these pictures affect Mac, iPhone or Android
What fujeigroup.com (AsyncRAT, stego PNG files) does on an infected PC
What we checked on 6 October 2026, and what we could not
We opened https://fujeigroup.com/ once, from Lithuania, in an automated Chromium browser set to English. The page did not load: the browser stopped with a TLS error (ERR_SSL_VERSION_OR_CIPHER_MISMATCH). That clears nothing, and it does not even test the addresses URLhaus lists, because those use plain http on port 8888.
Our site test, 6 October 2026
- The secure address did not answerChromium reported net::ERR_SSL_VERSION_OR_CIPHER_MISMATCH at https://fujeigroup.com/. That means the browser and the server could not agree on a secure connection. It can mean the server has no proper web page on the normal secure port. It tells you nothing about what sits on port 8888.
- Why that is not a clean resultA server that serves malware files on an odd port may have nothing at all on its front door. A quiet or broken home page is common for this kind of server and is not a sign of safety.
- Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded.
- URLhaus listingSeven picture files on port 8888 tagged stego; four tagged AsyncRAT and rat; all seven online in our copy of the data on 6 October 2026.
- Downloads and the files themselvesWe did not download any picture and did not open the folder listing. We cannot tell you what the files contain.
Dangerous: treat it as a malware server Our test was one visit that ended in a connection error, so it proves nothing either way. The danger rating comes from the seven URLhaus reports and their tags, not from our visit. Do not request files from this address and do not run anything that does.
What happened to fujeigroup.com, from registration to our test
The domain is almost a year old, but the reports are all from the last week. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.
20 October 2025
The domain is registered
RDAP shows fujeigroup.com registered on 20 October 2025 through NameCheap, Inc. The registration is due to expire on 20 October 2026, two weeks after our test.
16 August 2026
The record changes
RDAP shows the domain record last changed on 16 August 2026. It does not say what changed, so we draw no conclusion from it.
30 September 2026
Four picture files are reported
At about 10:05 UTC abuse.ch adds img_031721.png, img_173933.png, img_193047.png and img_200150.png. All four are tagged opendir and stego; img_200150.png is also tagged AsyncRAT and rat. The opendir tag says the folder could be browsed openly.
5 October 2026
Two more files, both tagged AsyncRAT
img_194859.png is added at about 09:17 UTC and img_010950.png at about 09:52 UTC, both tagged AsyncRAT, rat and stego. The opendir tag is no longer on them.
6 October 2026
A seventh file, and our test
img_202422.png is added at about 08:15 UTC with the tags AsyncRAT, rat and stego. All seven files are still marked online. Our own test of the secure home page the same day ends in a TLS error.

All seven URLhaus entries for fujeigroup.com on 6 October 2026. The file names change; the folder, the port and the tags stay the same.
What the pattern suggests, and what it does not: new file names keep appearing on the same folder and port within a week, which looks like an operator who keeps preparing fresh files rather than a single leftover. That is our reading of the dates, not something any report says.
How a picture file can carry a remote access trojan
A picture that hides code cannot hurt you by being opened or looked at. It works only when a loader that is already running reads the hidden part and starts it. We did not see the files on fujeigroup.com; this is how Seqrite, Splunk and MITRE describe the technique.

- 1
A first program is already running
In the campaigns vendors describe, it starts with a phishing email. Seqrite (17 March 2025) describes Excel documents that make the PC request an .hta file with VBScript in it. Splunk (27 March 2023) describes OneNote attachments and a downloaded .HTA file. In both, a script fetches the next piece.
- 2
It fetches a picture
Seqrite found harmless-looking JPG files that hide base64 text between the markers <<BASE64 START>> and <<BASE64 END>>. The script searches the downloaded picture for those markers and decodes what is between them. Splunk (11 August 2025) describes another way: code stored in the colour values of each pixel, about three bytes per pixel.
- 3
The hidden part is a program
In Seqrite's case the decoded text is a .NET library that pretends to be a Microsoft task scheduler file. In Splunk's case the decoded bytes are a Windows program. Either way the picture itself never contains a file ending in .exe, which is why a filter that only looks at file type sees an ordinary image.
- 4
It is started inside a trusted process
Seqrite describes process hollowing: the loader starts a genuine Windows program such as caspol.exe or msbuild.exe and replaces its contents with the malware. Microsoft's AsyncRAT entry names RegSvcs.exe the same way. In Task Manager the process then carries a trusted name.
- 5
The trojan connects to its controller
From then on a person elsewhere can use the PC through AsyncRAT: watch the screen, log keystrokes and take files. The next section lists what the sources say it does.
MITRE says this technique, listed as T1027.003, cannot easily be prevented with controls, because it abuses ordinary features of files. That is why the useful defences are earlier (do not run the first program) and later (notice the trojan and the connection).
What AsyncRAT is
AsyncRAT is a remote access tool that was published openly for anyone to download and is now used by many criminals. The sources agree on what it does and differ in what each campaign adds around it.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | An open-source remote access tool, first on GitHub under the name NYANxCAT, that has been used in malicious campaigns | MITRE ATT&CK S1087, modified 12 May 2026 |
| How old is it? | Splunk says it was released as open source in January 2019 | Splunk, 27 March 2023 |
| What does it do? | Keylogging, screen capture, file search and download, process control, reconnaissance of the system; Splunk adds remote camera access and browser credential theft | MITRE; Splunk |
| How does it stay? | Scheduled tasks or a registry Run key, according to Splunk and Microsoft; MITRE lists scheduled tasks. Seqrite found samples with empty persistence values, so not every build stays | Splunk; Microsoft; MITRE; Seqrite |
| How does it hide? | Sandbox and debugger checks, hollowing into trusted Windows programs, and encrypted traffic to its controller | MITRE; Microsoft; Splunk |
| Who uses it? | MITRE names TA2541, APT-C-36 and MirrorFace among the groups; the loaders vendors describe also deliver Remcos, AgentTesla, VIPKeyLogger and DcRAT in the same chains | MITRE; Seqrite |
| Is every sample real? | No. LevelBlue (2024) found a loader campaign whose delivered AsyncRAT samples were decoy clients with only loopback addresses. We do not know whether fujeigroup.com's files are real or decoys | LevelBlue SpiderLabs |
| Which build is this site's? | Not known. URLhaus gives only the tag AsyncRAT; we did not open the files | Not available |
What fujeigroup.com (AsyncRAT, stego PNG files) can steal or download
What AsyncRAT can take from a Windows PC
A remote access trojan gives a person a seat at your computer, so the list below is what such a person can do rather than what one build does automatically. Each item is named by at least one of the sources; no single report lists all of them.
Reported as possible
- Every key you type
- A live view and recording of your screen
- Your webcam
- Saved browser passwords
- Cryptocurrency wallet data
- Files searched for and downloaded
- Files uploaded, deleted, copied or renamed
- Running programs started or stopped
- Archives made with 7z before taking
- Your PC used as a relay for other attacks
- Extra malware downloaded
| Data | Detail | Source |
|---|---|---|
| Keystrokes and screen | Keylogging, desktop recording and screen capture | Splunk; MITRE |
| Camera | Remote camera access | Splunk |
| Logins | Credentials from browsers and from cryptocurrency wallets | Splunk; Microsoft |
| Files | File search, upload, delete, copy, rename and 7z archiving | Splunk |
| Control | Process management, extra downloads and chat with the victim | Splunk; MITRE |
| Proxy | Microsoft says the infected device can be turned into a proxy for further attacks | Microsoft |
What this can cost you
Reading the site or seeing its name costs nothing. The risks below apply to a Windows PC where a loader fetched one of these pictures and AsyncRAT then ran.
- High
Passwords and accounts
A keylogger records what you type into every site, including the new passwords you set. Changing passwords from the infected PC does not help; the person watching sees the new ones too.
- High
Someone using your PC live
A remote access trojan is not a one-off theft. The controller can come back at any time, watch the screen and act while you are logged in.
- High
Crypto and banking
Microsoft names wallet credential theft. Crypto sent from a stolen wallet cannot be reversed. A bank session that you opened on the PC can be watched.
- Medium
Your files and your camera
Splunk lists file search and download and remote camera access. Private documents and images on the PC are exposed.
- Medium
More malware on the same PC
The loaders in these campaigns also deliver other families (Seqrite names Remcos, AgentTesla, VIPKeyLogger and DcRAT), and AsyncRAT itself can download files.
- Low
Nothing, if you only saw the name
A name in a block list, a log or a warning is not an infection.
What you may notice, and what you may not
Remote access trojans are built to be quiet. The signs below come from the sources and from what they imply; none is certain, and most victims notice nothing.
| Sign | What the reports show |
|---|---|
| A scheduled task or startup entry you did not make | Splunk, Microsoft and MITRE all say AsyncRAT uses scheduled tasks or a registry Run key to start again after a restart |
| A trusted program running when it should not | Microsoft and Seqrite describe the trojan hiding inside RegSvcs.exe, caspol.exe or msbuild.exe. These are normal Windows programs, so one running with no reason, or using a lot of network, is worth a look |
| A Defender detection with the name AsyncRAT | Microsoft's name for a family of builds is Backdoor:MSIL/AsyncRAT!MTB, where MTB means it was caught by behaviour, not by a fixed signature |
| Your webcam light on, or the mouse moving | The tool can use the camera and the screen. This follows from the listed features; it is our reading, not a quote |
| Accounts you did not touch | Logins from new places, password reset emails and messages sent from your accounts. This follows from stolen logins |
| Nothing at all | Stealth is the point of a loader that runs in memory |
How to check the PC for fujeigroup.com (AsyncRAT, stego PNG files)
How a person ends up asking for these pictures
Nobody visits fujeigroup.com on purpose. The request comes from a program, so the real question is how that program got on the PC. We cannot say for this server; the routes below are the ones the vendors found with the same technique.
- 1
An Office attachment that wants macros or content
Seqrite describes Excel files that make the PC fetch an .hta file, and Splunk describes OneNote files. Opening the file and clicking to allow content or to open an embedded item is what starts it.
- 2
Software bundles and fake files
Microsoft says AsyncRAT typically spreads through phishing and software bundles that pose as legitimate files.
- 3
A link on a web page
LevelBlue describes an AsyncRAT loader campaign that began with an SVG attachment sending the victim to a web page that served obfuscated JavaScript.
Check your PC before you delete anything
Start with the question that matters: did something on this PC contact fujeigroup.com, or did you open an unexpected Office attachment, script or installer? If you saw the name in a firewall or DNS log from your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto. Microsoft's entry tells people to disconnect from all networks right away; do that if you can.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable. A remote access trojan needs the connection to be used.
- 2
Find which device asked for the address
If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question, not every device on the network.
- 3
Open Task Scheduler
Press Start, type Task Scheduler and open it. Look in Task Scheduler Library for tasks you do not know, with random names, or that run a script or a program from a user folder. Microsoft's entry points here first. Do not delete yet; write the name and the program it runs.
- 4
Look at the Run key and Startup apps
Microsoft names the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. Entries there start with your Windows sign in. A simpler view is Settings > Apps > Startup. Look for names you did not install.
- 5
Look for trusted programs that should not be running
Open Task Manager and look for RegSvcs.exe, caspol.exe or msbuild.exe running with no reason, or any process with a lot of network use. Microsoft and Seqrite name these as hiding places. Their presence is not proof (they are real Windows programs), and their absence does not clear the PC.
- 6
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for a detection called AsyncRAT or Backdoor:MSIL/AsyncRAT!MTB, or for anything blocked or quarantined at the time of the first contact. Microsoft says the results of an offline scan also appear there.
- 7
Check Defender exclusions
In Windows Security > Virus & threat protection > Manage settings > Exclusions, look for folders you did not add. Malware sometimes asks for exclusions so it is not scanned. We did not find a source for this specific campaign doing it, so a clean list does not clear the PC.
- 8
Check your accounts from another device
Look at the sign in activity of your email, bank and exchange accounts, and at crypto balances. This is quicker than any file check.
- 9
A scan helps, but it does not clear the PC
A scan with Microsoft Defender or another product can find known files. Treat a clean result the way you treat a clean site test: one data point. No vendor publishes a removal procedure for this server's files and we did not infect a PC, so the order of the plan is our judgement from Microsoft's pages and entry, not a tested result.
How to remove fujeigroup.com (AsyncRAT, stego PNG files)
How to remove fujeigroup.com
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to fujeigroup.com or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever fujeigroup.com installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The tags and every source we read describe a Windows threat. We found nothing that says the pictures on fujeigroup.com affect anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | Microsoft describes AsyncRAT as a Windows .NET program. The loaders in the reports use Windows scripts and Windows programs | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source describes AsyncRAT on iOS | Nothing to remove. If you typed passwords on a page, change them |
| Android | No source mentions it | Nothing to remove for this threat; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything you typed or stored on it while the trojan was there. The order matters: another device first, then the PC.

- 1
Change passwords from a clean device
Microsoft's entry says to change all passwords on a clean device. Start with email, because it resets everything else, then bank, work, cloud storage and crypto. Anything typed on the PC while it was watched is already known.
- 2
Sign out other sessions and turn on two step sign in
The FTC says to sign out of the account on all devices and to turn on two factor authentication if it is offered, so a password alone does not let anyone in. Update the recovery email and phone while you are there.
- 3
Move crypto first if a wallet was on the PC
If a seed phrase or wallet file was ever on the PC, assume it is known. Create a new wallet and recovery phrase on a clean device and move the funds there.
- 4
Run Microsoft Defender Offline
Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. It runs outside the normal Windows, so malware has a harder time hiding. Results are under Protection history. If BitLocker is on, Microsoft says to suspend it first or the restart may ask for the recovery key.
- 5
Remove what the check found, with care
If Task Scheduler or the Run key showed an entry that you can tie to the malware, Microsoft's entry says to delete it. If you cannot tell, do not guess: the safe answer is the reset below.
- 6
If you are not sure, reset Windows
Microsoft's recovery page puts the reset at Settings > System > Recovery > Reset this PC. Keep my files removes apps and settings but keeps personal files; Remove everything wipes the PC. For a PC that may have been under remote control, the full wipe is the answer that does not depend on finding every piece. Microsoft calls the reset the most disruptive option and says to back up first.
- 7
Restore only documents by hand
Copy back documents and photos, not programs, and not a full system image from after the first contact. Install apps from their makers' own sites.
- 8
Rebuild logins in a password manager
Do not let the browser save passwords again on a PC that was watched. Use a password manager and an authenticator app or security key for two step sign in.
- 9
Watch your money and your accounts
Check card statements and exchange logs for a few weeks. Turn on alerts. The FTC says to report stolen personal information at IdentityTheft.gov, which gives a recovery plan.
- 10
Tell the people you message
If your accounts were used to send links, tell your contacts not to open them.
Keep a PC out of this kind of chain
The picture is the late part of the chain. Every vendor write-up we read starts earlier, with a file or a script a person opened.
Do
- Treat an unexpected Office attachment that asks you to enable content or macros as an attack, and close it. Seqrite's campaign began with exactly that.
- Keep Windows and Microsoft Defender updated; the offline scan uses the latest definitions.
- Show file endings in File Explorer so a script posing as a document is visible.
- Get programs from their makers' own sites or from the Microsoft Store.
- Use a password manager and two step sign in, so one stolen password is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not open attachments from senders you do not expect, even when the file looks like an invoice or an order.
- Do not run cracked programs or bundles from sites that promise free versions of paid software.
- Do not rely on a file looking like a picture to be safe when a program, not you, is the one asking for it.
- Do not change your passwords on the PC you suspect.
- Do not rely on a quiet scan to say that you are safe.
Questions about fujeigroup.com (AsyncRAT, stego PNG files)
What is fujeigroup.com?
It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for seven picture files on port 8888 tagged stego. Four of them are also tagged AsyncRAT and rat.
The files were reported between 30 September and 6 October 2026. It is not a program on your PC and not a website anyone is meant to visit. We did not download the files, so what they contain is not confirmed by us.
Is fujeigroup.com safe to open?
No. Do not request files from it, and do not run anything that does.
Our own test of the secure home page failed with a TLS error, which proves nothing: the reported files are on plain http port 8888, and a server that hands out malware often has nothing on its front door. The rating comes from the seven URLhaus reports and their tags.
What does stego mean on a PNG file?
It is short for steganography, hiding data inside another file. Seqrite describes pictures that hide base64 text between markers, and Splunk describes code stored in the colour values of pixels.
The file still opens as an ordinary picture. A loader that is already running reads the hidden part, decodes it and starts it, so the picture is a carrier, not something that infects you by being viewed.
What is AsyncRAT?
AsyncRAT is a remote access tool, published as open source in 2019 and now used by many criminals. MITRE and Splunk list keylogging, screen capture, file search and download, process control and, in Splunk's list, camera access.
Microsoft adds browser and crypto wallet credential theft and says it can turn the PC into a proxy. It needs a loader to get onto the PC first.
I saw fujeigroup.com in my firewall or DNS log. Am I infected?
Not necessarily, and the name alone proves nothing. It does mean that a device on your network asked for it, and a person does not usually do that by hand. Find which device it was, disconnect it, and run the checks on this page:
- Task Scheduler
- Startup apps
- the Run key
- Protection history
- a Microsoft Defender Offline scan
Do the account changes from another device.
How do I remove AsyncRAT from Windows?
Change your passwords from another device first. Then run a Microsoft Defender Offline scan (Windows Security, Virus and threat protection, Scan options), check Task Scheduler and the Run key for entries you did not make, and delete the ones you can tie to the malware.
If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages for this and did not test the steps on an infected PC.
What can AsyncRAT see and take?
According to MITRE, Splunk and Microsoft: your keystrokes, a live view of the screen, files it searches for and downloads, browser and wallet credentials, and, in Splunk's list, the camera.
The person in control decides what to take, and can come back later. Treat every password, every session login and every wallet on the PC as known, and change them from another device.
Does fujeigroup.com affect Mac, iPhone or Android?
We found nothing that says so. Microsoft describes AsyncRAT as a Windows .NET program and the loaders in the reports use Windows scripts and programs. On a Mac, iPhone or Android phone there is nothing to remove for this threat; if you typed a password on a suspicious page, change it.
Will resetting Windows remove it, and are my accounts safe afterwards?
A reset with Remove everything wipes the programs and startup entries, which is the answer that does not depend on finding every piece. It does not undo what was already taken.
Passwords, session logins and crypto seed phrases that the trojan saw stay exposed until you change them, from another device, and turn on two step sign in. Restore documents by hand, not a full system image.
Will Fortect remove fujeigroup.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For fujeigroup.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Microsoft Security Intelligence: Backdoor:MSIL/AsyncRAT!MTB (updated 2 December 2025) (read October 6, 2026)
- MITRE ATT&CK: AsyncRAT, S1087 (modified 12 May 2026) (read October 6, 2026)
- MITRE ATT&CK: Obfuscated Files or Information, Steganography, T1027.003 (modified 12 May 2026) (read October 6, 2026)
- Splunk: AsyncRAT Crusade, Detections and Defense (27 March 2023) (read October 6, 2026)
- Splunk: Picture Paints a Thousand Codes, image steganography in a .NET (Quasar) RAT loader (11 August 2025; a different RAT, used for the pixel technique) (read October 6, 2026)
- Seqrite: New Steganographic Campaign Distributing Multiple Malware Variants (17 March 2025) (read October 6, 2026)
- Security Arsenal: AsyncRAT and Remcos steganography campaign, OTX pulse analysis (5 July 2026; a secondary summary of a campaign, used only for the Excel, HTA and PowerShell chain) (read October 6, 2026)
- LevelBlue SpiderLabs: AsyncRAT loader, obfuscation, DGAs, decoys and GOVNO (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 6, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 6, 2026)
- FTC: Email or social media hacked? Here's what to do (read October 6, 2026)