Trojanized ScreenConnect installers evolve, dropping multiple RATs on a single machine
ID: 3d802e10-e53f-578e-b5ec-53844a3f7d42
STIX ID: report--3d802e10-e53f-578e-b5ec-53844a3f7d42
Feed Name: TRU Security by Acronis
**Executive summary:** Since March 2025 Acronis TRU observed an increase in campaigns using trojanized ConnectWise ScreenConnect ClickOnce installers to gain initial access to mainly U.S. organizations; attackers rapidly deploy multiple RATs (AsyncRAT, a custom PowerShell RAT, PureHVNC/Remcos) via ScreenConnect automation, employ evolving loaders and persistence (batch/VBS/.NET assemblies, scheduled tasks), reuse preconfigured Windows Server VMs and phishing-themed filenames, and expose multiple IoCs and recommended mitigations such as monitoring RMM usage and scrutinizing ScreenConnect deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
