Close Menu
    What's Hot

    Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

    For Congo Fans, the Thrill of Victory Was so Close, Until It Wasn’t

    Apple is reportedly planning new iPad Pro and MacBook Pro releases early next year

    Facebook X (Twitter) Instagram
    Trending
    • Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
    • For Congo Fans, the Thrill of Victory Was so Close, Until It Wasn’t
    • Apple is reportedly planning new iPad Pro and MacBook Pro releases early next year
    • AMD: EPYC, Not Instinct, Is Leading AI Growth (NASDAQ:AMD)
    • Publishers can’t control AI answers. They can’t ignore them either
    • Immigrant Arrests Surge to 10,000 in 5 Days as ICE Clamps Down
    • Bureau of Prisons Will Close Facilities Housing Thousands of Inmates
    • Belgium stage 3–2 comeback win over Senegal to enter World Cup last 16 | World Cup 2026 News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

    adminBy adminJuly 1, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 01, 2026Malware / SEO Poisoning

    SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

    Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT.

    Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites.

    These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others. The Russian cybersecurity company said it identified more than 90 domain names localized across 10 languages, including English, Russian, Chinese, German, French, Spanish, Portuguese, and Arabic. Some of these domains were set up between August 2025 and March 2026.

    “The malicious archives bundle a legitimate, signed Microsoft install.exe binary alongside a rogue install.res.1033.dll library,” security researcher Denis Kulik said. “It is loaded onto the device via DLL side-loading and deploys the ScreenConnect service, which awaits further instructions from the threat actors.”

    Cybersecurity

    “This allowed the attackers to maintain control over compromised endpoints, with victims ranging from individual users to organizations.”

    Once ScreenConnect is up and running, the service creates and executes a PowerShell script (“Fj5NmEsp9EuKrun.ps1”), which configures Microsoft Defender exclusions, disables User Account Control (UAC) prompts, and then creates a Visual Basic Script (VBScript) file called “installer_method3_stream.vbs.”

    The script, for its part, creates a set of five files in the “C:\Users\Public directory” –

    • msgbox.txt
    • secret_bytes.txt
    • 1.vb
    • cap.ps1
    • script.vbs

    In the next stage, it triggers the execution of “script.vbs,” a script that’s responsible for terminating all active PowerShell processes and running “cap.ps1” in a hidden window. The primary goal of the PowerShell script is to read the contents of the “secret_bytes.txt” file, extract from it the AsyncRAT module, and run it using process hollowing.

    Cybersecurity

    The malware then establishes a connection to a remote server (“mora1987.work[.]gd”), allowing the threat actor to covertly control infected Windows systems, steal sensitive data, and monitor user activity by recording screen content.

    Persistence is established by means of a scheduled task (“MasterPackager.Updater”) that’s activated every two minutes to execute “script.vbs,” ensuring that the entire attack is run after a system reboot.

    “The threat actor disguises ScreenConnect as popular utilities and distributes it through fraudulent websites that mimic official product pages,” Kaspersky said. “The attackers leverage search engine optimization techniques to push these sites to the top of search results in engines like Google and Bing.”

    abuse AsyncRAT deploy ScreenConnect SEOPoisoned sites Software
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleMan Killed by Crocodile at a Popular Resort City in Mexico
    Next Article England 2-1 DR Congo player ratings: Harry Kane and Anthony Gordon save the day as Djed Spence struggles at right-back | Football News
    admin
    • Website

    Related Posts

    Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

    July 2, 2026

    VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

    July 2, 2026

    19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

    July 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

    For Congo Fans, the Thrill of Victory Was so Close, Until It Wasn’t

    Apple is reportedly planning new iPad Pro and MacBook Pro releases early next year

    AMD: EPYC, Not Instinct, Is Leading AI Growth (NASDAQ:AMD)

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by