SEO Poisoning Campaign Targets Users with AsyncRAT via Fake App Downloads

SEO Poisoning Campaign Targets Users with AsyncRAT via Fake App Downloads

First seen 23 Mar 2026, 21:46 UTC GbhackersCybersecuritynews 66.5

Article Content

Browse articles
ThreatCluster

Since October 2025, a sophisticated SEO poisoning campaign has been targeting Windows users by impersonating over 25 popular software applications. The attackers have been using trojanized installers to deliver the AsyncRAT remote access trojan, compromising victims' systems. This operation remained undetected for approximately five months until it was uncovered in March 2026. The campaign employs a variety of fake download portals to lure users into downloading malicious software. The scope of the impact is significant, affecting a wide range of users who unknowingly downloaded these trojanized applications. Investigators are currently assessing the full extent of the compromise. As of March 2026, the campaign is still active, posing a continuing threat to unsuspecting users. Security professionals are urged to be vigilant and educate users about the risks of downloading software from unverified sources.

Key Points: • The campaign has been active since October 2025, targeting Windows users. • Over 25 popular applications are being impersonated to deliver AsyncRAT. • The operation remained undetected for five months before being uncovered in March 2026.

Timeline

2025-10-01
SEO poisoning campaign begins targeting users.
2025-10-15
Trojanized installers for popular apps start being distributed.
2026-03-01
Investigators begin uncovering the scope of the campaign.
2026-03-23
Articles published detailing the campaign and its impact.