Malware · 75 days ago
Attackers are using the trust built into signed software and normal download habits against users. The lure is a popular app install, but the package drops a real ScreenConnect service first, then uses that foothold to keep control and deliver AsyncRAT later.
Kaspersky tied one ScreenConnect incident to a broader campaign built around more than 90 spoofed domains in 10 languages. The archives paired a legitimate signed installer with a rogue DLL so the malicious code loaded first, and the same playbook was used across fake sites posing as common apps like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.
The risk is a distribution network that can start as an ordinary-looking software install and end with remote admin access on the endpoint. Teams that trust signed installers or support remote-admin tools in normal workflows are being targeted through that exact trust chain.
2 sources covering this story
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Kaspersky says 90+ spoofed domains use malicious installers and SEO to deliver AsyncRAT to Windows systems through ScreenConnect.
How a single ScreenConnect incident exposed a massive campaign
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT.
Part of the PlainSec briefing for 2026-07-02