HomeSecurityMalicious software sites use ScreenConnect to deploy AsyncRAT

Malicious software sites use ScreenConnect to deploy AsyncRAT

Unknown malicious actors are exploiting the ScreenConnect to deploy and execute AsyncRAT, an activity that has raised concerns in the global cybersecurity community.

ScreenConnect for AsyncRAT deployment

ScreenConnect Abuse

Kaspersky said this activity is part of a “massive, multi-sector, multi-lingual” campaign that distributes malicious installation files via fake websites. These files pretend to be popular software such as OBS Studio, DNS Jumper, DS4Windows, and Bandicam, thereby misleading users into downloading them.

The Russian cybersecurity firm identified more than 90 domain names in 10 languages, including English, Russian, Chinese, German, French, Spanish, Portuguese, and Arabic. The creation of these domains took place between August 2025 and March 2026, indicating careful and long-term preparation by the attackers.

See also: AsyncRAT exploits ConnectWise ScreenConnect

Security researcher Denis Kulik explained that the malicious files include a legitimate, signed Microsoft installation executable along with a malicious install.res.1033.dll. This is loaded onto the device via DLL side-loading, a method that allows malicious code to be executed via legitimate applications. This way, attackers can maintain control over compromised systems, with victims ranging from individual users to organizations.

Once ScreenConnect is operational, the service creates and runs a PowerShell script (“Fj5NmEsp9EuKrun.ps1”), which sets up exceptions in Microsoft Defender, disables User Account Control (UAC) prompts , and creates a Visual Basic Script (VBScript) named “installer_method3_stream.vbs.” These actions allow attackers to bypass system security measures and maintain their presence without being easily detected.

The script creates a set of five files in the directory "C:\Users\Public": msgbox.txt, secret_bytes.txt, 1.vb, cap.ps1, script.vbs.

In the next stage, it triggers the execution of “script.vbs”, which terminates all active PowerShell processes and runs “cap.ps1” in a hidden window. The main goal of the PowerShell script is to read the contents of the “secret_bytes.txt” file, extract the AsyncRAT , and execute it using the process hollowing. This technique allows the malware to replace the memory of a legitimate process with malicious code, making detection even more difficult.

See also: Kimsuky hackers use ScreenConnect bugs to distribute ToddleShark malware

Malicious software sites use ScreenConnect to deploy AsyncRAT

AsyncRAT malware

The malware establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the malicious actor to secretly control infected Windows systems, steal sensitive data, and monitor user activity by recording screen content. This capability allows attackers to collect information such as passwords, financial data, and other sensitive information.

As for persistence, it is achieved through a scheduled task (“MasterPackager.Updater”) that is triggered every two minutes to execute “script.vbs”, ensuring that the entire attack is executed after a system reboot. This constant presence of the malware makes it difficult to remove from the system and allows attackers to maintain access for long periods of time.

See also: Malicious use of ScreenConnect allows remote access

Kaspersky notes that malicious actors disguise ScreenConnect as popular tools and distribute it via deceptive websites that mimic official product pages. Attackers use search engine optimization techniques to promote these websites to the top of search results on engines like Google and Bing. This strategy increases the likelihood that users will visit the fake websites and download the malware, believing it to be legitimate software.

The ScreenConnect exploit in this campaign highlights the need for increased vigilance and enhanced security measures from users and organizations. Users should be particularly careful when downloading software from the internet, while organizations should invest in advanced detection and response systems to protect their networks from such threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS