Kaspersky: Major Campaign Uses Fake Free Software to Deploy RAT via ScreenConnect

A remote administration tool called ScreenConnect is being spread via counterfeit websites that resemble the legitimate pages of popular software programs.

Researchers discovered over 90 domains across 10 different languages, such as English, Arabic, Spanish, Chinese, German, Portuguese, and Russian, allowing the perpetrators to access numerous victims globally. This operation focuses on both personal users and companies utilizing Windows systems.

Following detection of an event via its Managed Detection and Response service, Kaspersky discovered a widespread operation where cybercriminals utilized counterfeit sites to distribute installation packages masquerading as well-known applications such as OBS Studio, DNS Jumper, DS4Windows, Glary Utilities, and Bandicam.

In order to attract visitors to these pages, the malicious individual also employed search engine optimization methods to rank them prominently in search outcomes.

Over 90 confirmed fake software websites used identical methods: individuals who installed what seemed like genuine applications ended up with a concealed ScreenConnect remote management tool, granting hackers continuous entry into affected devices and enabling them to install AsyncRAT, an open-source malware designed to provide complete control over hacked systems.

The number of domain registrations associated with this campaign reached its highest point in February 2026; during 2025, the same hacker employed counterfeit websites to conceal harmful installers as video games.

An infection happens when harmful archive files include a genuine, digitally certified Microsoft file called install.exe along with the install.res.1033.dll library. The DLL is introduced to the system using a method known as DLL sideloading, which then activates a ScreenConnect service ready to receive additional commands from the hackers.

The initiative focuses on individuals who download free software from the internet as well as corporate networks, where remote access programs are frequently permitted and provided with increased permissions.

"The risk comes from its ability to enable widespread stealing of credentials and unauthorized system access, with the obtained information often sold on dark web platforms afterward," notes Denis Kulik, head SOC Analyst at Kaspersky.

Supplied by SyndiGate Media Inc. ( Syndigate.info ).

Post a Comment

Previous Post Next Post