< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-01T23:23:06+05:30

AsyncRAT Deployment via SEO-Poisoned Software Sites Using ScreenConnect

Threat actors are exploiting SEO-poisoned software sites to distribute malicious installer archives that deploy the AsyncRAT Remote Access Trojan (RAT). This method leverages ScreenConnect for initial access and establishes persistence by executing PowerShell and VBScript commands on compromised endpoints.

Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT.

Kaspersky said the activity is part of a "massive, multi-domain, multi-language" campaign that distributes malicious installer archives hosted on spoofed websites.

These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others.

Read original article

*** END OF TRANSMISSION ***