SEO Poisoning and ScreenConnect Used as Bait for AsyncRAT

Colleagues, I’d like to draw attention to a cybersecurity development: threat actors are masquerading ScreenConnect as popular utilities and distributing AsyncRAT through fake websites.
Key points:
• Fraudulent pages are being promoted in search results through SEO poisoning.
• Inside the archive, a malicious DLL is placed alongside a legitimate installer.exe to enable DLL side-loading.
• Scripts then run to weaken defenses, add exclusions in Microsoft Defender, and establish persistence.
• As a result, attackers gain covert remote access and can collect data.
Why it matters: trust in search results and “signed” files is increasingly being used against us.
How do you verify software downloads for employees?
#cybersecurity #malware #AsyncRAT #SOC

