Signed Installers Hide a Remote-Control Malware Network
Attackers are using the trust built into signed software and normal download habits against users. The lure is a popular app install, but the package drops a real ScreenConnect service first, then uses that foothold to keep control and deliver AsyncRAT later.
Kaspersky tied one ScreenConnect incident to a broader campaign built around more than 90 spoofed domains in 10 languages. The archives paired a legitimate signed installer with a rogue DLL so the malicious code loaded first, and the same playbook was used across fake sites posing as common apps like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.
The risk is a distribution network that can start as an ordinary-looking software install and end with remote admin access on the endpoint. Teams that trust signed installers or support remote-admin tools in normal workflows are being targeted through that exact trust chain.