CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Trojanised ScreenConnect AsyncRAT campaign

campaign · campaign:screenconnect-asyncrat-seo-poisoning

SEO-poisoned fake-installer sites trojanising ScreenConnect to deploy AsyncRAT.

Coverage
1
first 2026-07-02 → last 2026-07-02
Latest activity
2026-07-02
Kaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
2
2 hosts

Defender insights

What each entry about Trojanised ScreenConnect AsyncRAT campaign tells a defender to do, newest first.

2026-07-02NOTABLEKaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT

Detection

Story timeline

  1. 2026-07-02Kaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT
    research
ATT&CK techniques (1 across 2 tactics)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Privilege EscalationProcess Injection: Process Hollowing
  • StealthProcess Injection: Process Hollowing

Privilege Escalation TA0004

T1055.012Process Injection: Process Hollowing×1

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-07-02/kaspersky-mdr-seo-poisoned-fake-installer-sites-trojanize-sc · ATT&CK page ↗

Stealth TA0005

T1055.012Process Injection: Process Hollowing×1

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-07-02/kaspersky-mdr-seo-poisoned-fake-installer-sites-trojanize-sc · ATT&CK page ↗

Entries about Trojanised ScreenConnect AsyncRAT campaign (1)

2026-07-02 · view entry permalink →

NOTABLE

Kaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT

Kaspersky's MDR team pivoted from a single flagged incident (suspicious PowerShell/VBS spawned by a ScreenConnect process) into a "massive, multi-domain, multi-language" campaign running since at least August 2025, using 90+ spoofed sites in ten languages (including German and French) impersonating free software such as OBS Studio, DNS Jumper and Bandicam (Kaspersky Securelist, 2026-07-01). Each malicious installer bundles a legitimate Microsoft-signed install.exe alongside a rogue install.res.1033.dll sideloaded via classic DLL search-order abuse; ScreenConnect deploys as an "Access-type" service, then a PowerShell script adds Defender path exclusions for all local drives and C:\Users\Public, disables the UAC consent prompt, and a chained VBScript reconstructs a .NET payload (XOR key 0xA7) that reflectively loads and process-hollows (T1055.012) into a suspended RegAsm.exe acting as the AsyncRAT container, with a two-minute scheduled-task re-trigger for persistence (The Hacker News, 2026-07-01). Detection/hardening: flag ScreenConnect service creation with an explicit relay parameter where the deploying process is a freshly-downloaded installer; alert on Defender exclusions covering full drive roots or C:\Users\Public added via PowerShell rather than GPO/MDM; treat long-lived RegAsm.exe with active network connections as a process-hollowing tell; block DLL sideloading via WDAC/AppLocker on signed binaries' unsigned companion DLLs.

research02 Jul 04:55Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • securelist.com1 (50%)
  • thehackernews.com1 (50%)