{"id":30774,"date":"2026-07-29T16:50:12","date_gmt":"2026-07-29T15:50:12","guid":{"rendered":"https:\/\/www.kaspersky.co.uk\/blog\/screenconnect-fake-software-campaign\/30774\/"},"modified":"2026-07-29T16:50:12","modified_gmt":"2026-07-29T15:50:12","slug":"screenconnect-fake-software-campaign","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.uk\/blog\/screenconnect-fake-software-campaign\/30774\/","title":{"rendered":"When ScreenConnect works for cybercriminals"},"content":{"rendered":"<p>Leveraging legitimate software is one of cybercriminals\u2019 tactics of choice, with remote management tools ranking among their top tools. A recent example involves the remote administration utility ScreenConnect. It\u2019s designed for IT support teams to troubleshoot systems and configure software seamlessly in the background. However, when weaponized by threat actors, ScreenConnect becomes a versatile attack vehicle used to harvest data, deploy malware, and move laterally across corporate networks.<\/p>\n<p>During a recent incident detected by <a href=\"https:\/\/www.kaspersky.co.uk\/enterprise-security\/managed-detection-and-response?icid=gb_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Kaspersky Managed Detection and Response<\/a>, our experts identified an attempt to use ScreenConnect in an attack. This allowed a <a href=\"https:\/\/securelist.com\/tr\/the-soc-files-screenconnect-campaign-with-asyncrat\/120472\/\" target=\"_blank\" rel=\"noopener\">detailed study<\/a> of how attackers used this application in a large-scale malware distribution campaign. The following breakdown illustrates the mechanics of ScreenConnect-assisted attacks, and outlines key strategies to defend your organization against them.<\/p>\n<h2>How ScreenConnect reaches target computers<\/h2>\n<p>In the campaign analyzed by our experts, the attackers bundled ScreenConnect with legitimate free business software. They established a network of phishing websites to spoof popular tools, including OBS Studio, DS4Windows, DNS Jumper, Glary Utilities, Bandizip, Process Hacker, and others.<\/p>\n<p>These rogue websites featured high-quality designs that could be taken for the official pages, making them highly convincing to unsuspecting users. Once the victim clicks the download button for the software, an archive is downloaded to their computer that contains additional files alongside the requested application:<\/p>\n<ul>\n<li>A legitimately signed Microsoft executable (<em>exe<\/em>), renamed to match the expected application installer (for example, <em>OBS-Studio-Installer.exe<\/em>)<\/li>\n<li>A malicious library named <em>res.1033.dll<\/em><\/li>\n<li>An Assets directory containing installers for both ScreenConnect and the intended application<\/li>\n<\/ul>\n<p>Launching the renamed file disguised as the app installer triggers DLL sideloading of a malicious library. This library silently runs the ScreenConnect installation without restarting the system, while using the standard Windows installer to set up the software the user originally tried to install.<\/p>\n<p>The attackers used search engine optimization techniques to drive traffic to their fake websites. As a result, these malicious pages appeared at the top of search results for certain free software utilities on major search engines.<\/p>\n<p>Our experts discovered over 90 domain names translated into more than 10 different languages. While most of these websites targeted English, Russian, and Chinese speakers, several domains catered to German, French, Spanish, Arabic, and other regional audiences.<\/p>\n<p>A detailed analysis of the IP addresses and associated spoofed domains is available in <a href=\"https:\/\/securelist.com\/tr\/the-soc-files-screenconnect-campaign-with-asyncrat\/120472\/\" target=\"_blank\" rel=\"noopener\">our technical research article<\/a> on Securelist, along with full indicators of compromise.<\/p>\n<h2>Why the attackers exploited ScreenConnect<\/h2>\n<p>In this campaign, attackers leveraged ScreenConnect to generate and execute malicious scripts on victim machines. These scripts served several key functions: they created exclusions for specific drives, directories, and processes within Windows Defender, disabled the User Account Control (UAC) security mechanism, and delivered and deployed AsyncRAT \u2013 a remote access Trojan.<\/p>\n<p>To maintain persistence, the scripts configured a Windows scheduled task to run the malicious code at preset intervals. AsyncRAT then established a connection with the attackers\u2019 command-and-control server to receive further instructions.<\/p>\n<p>The primary objective of this campaign appears to be gaining unauthorized access to enterprise systems, likely to then resell it on cybercrime marketplaces.<\/p>\n<h2>How to secure corporate infrastructure<\/h2>\n<p>Although ScreenConnect in and of itself is a legitimate tool, its presence poses a security risk to corporate environments. Consequently, <a href=\"https:\/\/www.kaspersky.co.uk\/next?icid=gb_kdailyplacehold_acq_ona_smm__onl_b2b_kdaily_wpplaceholder_sm-team___knext____c85c7f718828ada0\" target=\"_blank\" rel=\"noopener\">Kaspersky security solutions<\/a> detect this application as <em>not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen.<\/em><\/p>\n<p>Security teams should implement the following controls:<\/p>\n<ul>\n<li>Enforce strict application control policies, including software allowlisting and restrictions on MSI package installations from unverified sources<\/li>\n<li>Monitor for newly installed remote management utilities and scheduled tasks<\/li>\n<li>Filter outbound network traffic from workstations to unknown IP addresses and domains<\/li>\n<\/ul>\n<p>As noted previously, this campaign was originally detected through the <a href=\"https:\/\/www.kaspersky.co.uk\/enterprise-security\/managed-detection-and-response?icid=gb_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Kaspersky Managed Detection and Response service<\/a>, which can be employed to protect against such threats.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"mdr\">\n","protected":false},"excerpt":{"rendered":"<p>How attackers distribute ScreenConnect under the guise of free software to deploy AsyncRAT.<\/p>\n","protected":false},"author":2726,"featured_media":30775,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1836,2360,2361],"tags":[111,1886,2904,722,2369,529,698,113],"class_list":{"0":"post-30774","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-enterprise","9":"category-smb","10":"tag-attacks","11":"tag-defender","12":"tag-mdr","13":"tag-rat","14":"tag-soc","15":"tag-threats","16":"tag-trojans","17":"tag-windows"},"hreflang":[{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/screenconnect-fake-software-campaign\/30774\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/screenconnect-fake-software-campaign\/30944\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/screenconnect-fake-software-campaign\/25973\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/screenconnect-fake-software-campaign-2\/42392\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/screenconnect-fake-software-campaign\/56197\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/screenconnect-fake-software-campaign-2\/30904\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/screenconnect-fake-software-campaign\/36439\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/screenconnect-fake-software-campaign\/36335\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.uk\/blog\/tag\/rat\/","name":"RAT"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=30774"}],"version-history":[{"count":0,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30774\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media\/30775"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=30774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=30774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=30774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}