Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

The Hacker News by The Hacker News
July 1, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananJul 01, 2026Malware / SEO Poisoning

Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT.

Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites.

These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others. The Russian cybersecurity company said it identified more than 90 domain names localized across 10 languages, including English, Russian, Chinese, German, French, Spanish, Portuguese, and Arabic. Some of these domains were set up between August 2025 and March 2026.

“The malicious archives bundle a legitimate, signed Microsoft install.exe binary alongside a rogue install.res.1033.dll library,” security researcher Denis Kulik said. “It is loaded onto the device via DLL side-loading and deploys the ScreenConnect service, which awaits further instructions from the threat actors.”

“This allowed the attackers to maintain control over compromised endpoints, with victims ranging from individual users to organizations.”

Once ScreenConnect is up and running, the service creates and executes a PowerShell script (“Fj5NmEsp9EuKrun.ps1”), which configures Microsoft Defender exclusions, disables User Account Control (UAC) prompts, and then creates a Visual Basic Script (VBScript) file called “installer_method3_stream.vbs.”

The script, for its part, creates a set of five files in the “C:UsersPublic directory” –

  • msgbox.txt
  • secret_bytes.txt
  • 1.vb
  • cap.ps1
  • script.vbs

In the next stage, it triggers the execution of “script.vbs,” a script that’s responsible for terminating all active PowerShell processes and running “cap.ps1” in a hidden window. The primary goal of the PowerShell script is to read the contents of the “secret_bytes.txt” file, extract from it the AsyncRAT module, and run it using process hollowing.

The malware then establishes a connection to a remote server (“mora1987.work[.]gd”), allowing the threat actor to covertly control infected Windows systems, steal sensitive data, and monitor user activity by recording screen content.

Persistence is established by means of a scheduled task (“MasterPackager.Updater”) that’s activated every two minutes to execute “script.vbs,” ensuring that the entire attack is run after a system reboot.

“The threat actor disguises ScreenConnect as popular utilities and distributes it through fraudulent websites that mimic official product pages,” Kaspersky said. “The attackers leverage search engine optimization techniques to push these sites to the top of search results in engines like Google and Bing.”



Source link

The Hacker News

The Hacker News

Next Post
FuelRod Expands Swappable Power Network Across San Diego’s Top Visitor Destinations

FuelRod Expands Swappable Power Network Across San Diego's Top Visitor Destinations

Recommended.

VCTI Accelerates Service Provider Enterprise Sales With Broadband IQ™

VCTI Accelerates Service Provider Enterprise Sales With Broadband IQ™

May 14, 2025
Stocks making the biggest moves midday: Lyft, Walmart, Nvidia, Baidu and more

Stocks making the biggest moves midday: Lyft, Walmart, Nvidia, Baidu and more

September 17, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio