Cybersecuritynews SEO Poisoning Campaign Targets Users with AsyncRAT via Fake App Downloads
Article Content
- •The campaign has been active since October 2025, targeting Windows users.
- •Over 25 popular applications are being impersonated to deliver AsyncRAT.
- •The operation remained undetected for five months before being uncovered in March 2026.
Since October 2025, a sophisticated SEO poisoning campaign has been targeting Windows users by impersonating over 25 popular software applications. The attackers have been using trojanized installers to deliver the AsyncRAT remote access trojan, compromising victims' systems. This operation remained undetected for approximately five months until it was uncovered in March 2026. The campaign employs a variety of fake download portals to lure users into downloading malicious software. The scope of the impact is significant, affecting a wide range of users who unknowingly downloaded these trojanized applications. Investigators are currently assessing the full extent of the compromise. As of March 2026, the campaign is still active, posing a continuing threat to unsuspecting users. Security professionals are urged to be vigilant and educate users about the risks of downloading software from unverified sources.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AsyncRAT and SideCopy Campaigns Target Users with Multi-Stage Attacks Recent cybersecurity reports detail two significant malware campaigns involving AsyncRAT and SideCopy. The AsyncRAT campaign employs a five-stage infection chain utilizing a socially engineered batch file and the AutoIt interpreter, culminating in a .NET payload that steals information. Meanwhile, the SideCopy group…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…