Feeds.Feedburner Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
Article Content
- •Attackers exploit ScreenConnect to deploy AsyncRAT through fake software installers.
- •Over 90 spoofed domains in 10 languages were used to distribute malicious installers.
- •The attack chain includes DLL sideloading and process hollowing for stealthy persistence.
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as popular software like OBS Studio and Bandicam, to distribute malicious installers. Over 90 domain names in 10 languages were identified, each containing a legitimate Microsoft-signed executable bundled with a rogue DLL. The attack employs DLL sideloading to install the ScreenConnect service, which then executes PowerShell and VBScript to disable security measures and establish persistence. This campaign has affected both individual users and organizations, allowing attackers to maintain covert control over compromised systems. The operation was discovered by Kaspersky's Managed Detection and Response team, which continues to investigate the extensive command and control infrastructure behind the attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AsyncRAT and SideCopy Campaigns Target Users with Multi-Stage Attacks Recent cybersecurity reports detail two significant malware campaigns involving AsyncRAT and SideCopy. The AsyncRAT campaign employs a five-stage infection chain utilizing a socially engineered batch file and the AutoIt interpreter, culminating in a .NET payload that steals information. Meanwhile, the SideCopy group…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…