{"id":1559,"date":"2026-07-01T19:07:01","date_gmt":"2026-07-01T19:07:01","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1559"},"modified":"2026-07-01T19:07:01","modified_gmt":"2026-07-01T19:07:01","slug":"seo-poisoned-software-sites-abuse-screenconnect-to-deploy-asyncrat","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1559","title":{"rendered":"SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 01, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ SEO Poisoning<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhbKfADFEhazeaRztmVJkTBhFqZxALUDBwsOV_25bWjZ6Qm3pCBoSSawssWOOJC2ZQ7M6hrUDRXLfR5gcpWRkkaSdNtSPCz-FLrG5Dy4-Y-IzEMt_souSqJuc3JK9FNQ9p2-dT7Ojf3ufzPkWBpLNyDAVeeuYS7Ya-BJWT4MmAHz7OjHvwjMSCfF5Jvahyphenhyphenj\/s1700-e365\/SEO-MALWARE.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute <a href=\"https:\/\/www.forcepoint.com\/blog\/x-labs\/asyncrat-reloaded-python-trycloudflare-malware\">AsyncRAT<\/a>.<\/p>\n<p>Kaspersky said the activity is part of a \u00abmassive, multi-domain, multi-language\u00bb campaign that distributes malicious installer archives hosted on spoofed websites.<\/p>\n<p>These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others. The Russian cybersecurity company said it identified more than 90 domain names localized across 10 languages, including English, Russian, Chinese, German, French, Spanish, Portuguese, and Arabic. Some of these domains were set up between August 2025 and March 2026.<\/p>\n<p>\u00abThe malicious archives bundle a legitimate, signed Microsoft install.exe binary alongside a rogue install.res.1033.dll library,\u00bb security researcher Denis Kulik <a href=\"https:\/\/securelist.com\/tr\/the-soc-files-screenconnect-campaign-with-asyncrat\/120472\/\">said<\/a>. \u00abIt is loaded onto the device via DLL side-loading and deploys the ScreenConnect service, which awaits further instructions from the threat actors.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThis allowed the attackers to maintain control over compromised endpoints, with victims ranging from individual users to organizations.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Once ScreenConnect is up and running, the service creates and executes a PowerShell script (\u00abFj5NmEsp9EuKrun.ps1\u00bb), which configures Microsoft Defender exclusions, disables User Account Control (UAC) prompts, and then creates a Visual Basic Script (VBScript) file called \u00abinstaller_method3_stream.vbs.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1hJV3xz-yT0czNtUzFEoirdeGaAA3zWuPLvZSpnXDBCK_TlksWOkQQYZlaZ2_E_R5D-eW4dzTGldz3eLcxESWP5DzWq1X4PQ0o3T5mOevVyH-khqq1R6tOo8UFvczB5Z-qy7YbgTI1BUG_gVSFGdkewhOLxltxRqObEXyCU5ABzoRtH7iUJkRO6a42XGn\/s1700-e365\/ss.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1hJV3xz-yT0czNtUzFEoirdeGaAA3zWuPLvZSpnXDBCK_TlksWOkQQYZlaZ2_E_R5D-eW4dzTGldz3eLcxESWP5DzWq1X4PQ0o3T5mOevVyH-khqq1R6tOo8UFvczB5Z-qy7YbgTI1BUG_gVSFGdkewhOLxltxRqObEXyCU5ABzoRtH7iUJkRO6a42XGn\/s1700-e365\/ss.png\" alt=\"\" border=\"0\" data-original-height=\"887\" data-original-width=\"1916\"\/><\/a><\/div>\n<p>The script, for its part, creates a set of five files in the \u00abC:\\Users\\Public directory\u00bb &#8211;<\/p>\n<ul>\n<li>msgbox.txt<\/li>\n<li>secret_bytes.txt<\/li>\n<li>1.vb<\/li>\n<li>cap.ps1<\/li>\n<li>script.vbs<\/li>\n<\/ul>\n<p>In the next stage, it triggers the execution of \u00abscript.vbs,\u00bb a script that&#8217;s responsible for terminating all active PowerShell processes and running \u00abcap.ps1\u00bb in a hidden window. The primary goal of the PowerShell script is to read the contents of the \u00absecret_bytes.txt\u00bb file, extract from it the AsyncRAT module, and run it using <a href=\"https:\/\/attack.mitre.org\/techniques\/T1055\/012\/\">process hollowing<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-2\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhr7HGzx4ULDSqwnN820pPGxlPxqqVxKgIrI5II1iWdspOL6yHZsdB5lWoXU3LmhIU4dtnph89fLZ0CxrQSs-ufs6Mo4eD-d-Cpx-DsV1G15eC-phLACF7hyaKSIH1zIdj3AuD7lHSHnVelmKVMoVV-_zvtJuodsSIDKu6uSRfU6fZBkO-2PERqKSfIn6dA\/s728-e100\/sygnia-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The malware then establishes a connection to a remote server (\u00abmora1987.work[.]gd\u00bb), allowing the threat actor to covertly control infected Windows systems, steal sensitive data, and monitor user activity by recording screen content.<\/p>\n<p>Persistence is established by means of a scheduled task (\u00abMasterPackager.Updater\u00bb) that&#8217;s activated every two minutes to execute \u00abscript.vbs,\u00bb ensuring that the entire attack is run after a system reboot.<\/p>\n<p>\u00abThe threat actor disguises ScreenConnect as popular utilities and distributes it through fraudulent websites that mimic official product pages,\u00bb Kaspersky said. \u00abThe attackers leverage search engine optimization techniques to push these sites to the top of search results in engines like Google and Bing.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 01, 2026Malware \/ SEO Poisoning Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1560,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[383,507,229,863,2288,228,588],"class_list":["post-1559","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuse","tag-asyncrat","tag-deploy","tag-screenconnect","tag-seopoisoned","tag-sites","tag-software"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1559","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1559"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1559\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1560"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}