Security researchers have discovered a campaign distributing ScreenConnect malware through fake websites mimicking popular software. This operation targets both individual users and corporate networks running Windows operating systems. Meanwhile, the attackers use search engine optimization techniques to place these fraudulent pages high in search results.
How the ScreenConnect Malware Spreads
According to a report by cybersecurity firm Kaspersky, the campaign uses more than 90 domains spanning 10 languages. These languages include English, Arabic, Spanish, Chinese, German, Portuguese, and Russian. Consequently, the attackers can reach a wide range of victims globally.
The fraudulent sites distribute installer archives disguised as legitimate software. Specifically, these include OBS Studio, DNS Jumper, DS4Windows, Glary Utilities, and Bandicam. Victims who download these files unknowingly install a hidden remote administration tool.
Technical Details of the Infection
The infection process begins when a user downloads a malicious archive. This archive contains a legitimate, signed Microsoft file named install.exe alongside a library called install.res.1033.dll. Subsequently, the DLL is loaded onto the device via a DLL sideloading technique.
Once loaded, the library deploys a service that awaits further instructions from the attackers. This persistent access allows the threat actors to deploy AsyncRAT, an open-source trojan. As a result, the attackers gain full control over the infected Windows systems.
Analyst Insights on the Threat
The campaign poses a significant risk to corporate networks where remote access tools are often permitted.
“The campaign targets both users downloading free utilities from the internet and corporate networks, where remote access tools are often allowlisted and granted elevated privileges. Its danger lies in its potential to facilitate large-scale credential theft and unauthorized access to systems, with the stolen data typically later resold on dark web forums.”
Denis Kulik, lead SOC Analyst at Kaspersky
Recommended Mitigation Steps for ScreenConnect Malware
To mitigate the risks of this ScreenConnect malware, businesses should enforce strict software installation controls. For example, organizations can block MSI package installations from untrusted sources and monitor for new remote administration services. Furthermore, filtering outbound traffic to unknown domains helps prevent unauthorized connections.
Individual users should also remain cautious when downloading software from the internet. Specifically, users must verify the authenticity of website URLs and use strong security solutions. Additionally, enabling multi-factor authentication on all accounts helps protect sensitive data from unauthorized access.





