The emergence of a new campaign that exploits legitimate remote monitoring and management software has raised concerns among security teams worldwide. Attackers are distributing installers with modified code for ConnectWise ScreenConnect— now known as ConnectWise Control— to deliver two payloads: the widely used AsyncRAT and a custom PowerShell-.
See also: Real-time threat intelligence: Critical for modern SOCs

Using trusted software and open directories, hackers bypass signature-based defenses and maintain long-term access to compromised networks. The first incidents occurred in May 2025, when analysts observed malformed ScreenConnect installers hosted on compromised file servers. These installers contained ClickOnce that, when executed, would inject malicious components during execution rather than embedding the payloads directly. In one case, a compromised installer silently launched a VBS script that executed a modified shortcut, triggering PowerShell with an execution policy override to run a loader script.
Hunt.io Cyber Team researchers identified this tactic after correlating telemetry from multiple exposed computers and correlating indicators of compromise (IOCs) in open directories. Subsequent analysis revealed a recurring infrastructure pattern. The infected installers jumped to repositories hosting .zip files named logs.ldk, logs.idk, and logs.idr , which were extracted into dropper scripts (Ab.vbs or Ab.js), the PowerShell loader (Skype.ps1), a native DLL (libPK.dll), and a shortcut file (Microsoft.lnk).
See also: Warning: Serious vulnerabilities in NVIDIA NVDebug tool

The VBS launcher uses WScript.Shell to call the shortcut, which in turn runs PowerShell with hidden windows to launch Skype.ps1. This script recompiles an embedded payload, calls the Execute to natively load it into memory, and creates a scheduled task named SystemInstallTask for persistence. The infection chain begins with a seemingly innocent ScreenConnect client installer. Once executed, it drops the VBS loader (Ab.vbs) into a public folder and registers a Windows shortcut.
The shortcut target is designed to launch PowerShell with -ExecutionPolicy Bypass -WindowStyle Hidden, calling a small script file named Skype.ps1. Skype.ps1 contains base64 encoded payload segments that decode to a .NET assembly or native shellcode, depending on the detected security products. If the script detects antiviruses such as TotalAV or Avast, it performs assembly loading into memory via System.Reflection.Assembly.Load. Otherwise, it dynamically imports libPK.dll using PowerShell's Add-Type and calls Execute to inject payloads into legitimate host processes.
See also: AsyncRAT exploits ConnectWise ScreenConnect

To maintain resilience, the loader also schedules recurring tasks (every 2–10 minutes) ensuring quick re-execution if terminated. Additionally, the use of open directories for the initial staging phase allows attackers to rotate files and sectors frequently, complicating detection. The combination of modular scripts, scheduled tasks, and dual execution paths is an example of a sophisticated multi-layered delivery structure that combines the abuse of legitimate RMM software with customized RAT payloads.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
