Trojanized ScreenConnect installers evolve, dropping multiple RATs on a single machine
ID: d7de1861-55df-5f58-8b47-caaf51ca0d8c
STIX ID: report--d7de1861-55df-5f58-8b47-caaf51ca0d8c
Feed Name: TRU Security by Acronis
**Executive summary:** Acronis TRU reports an increase since March 2025 in campaigns abusing trojanized ConnectWise ScreenConnect installers (now using evasive ClickOnce runners) to establish access in U.S. networks and rapidly deploy multiple RATs—including AsyncRAT, a custom PowerShell RAT, PureHVNC and Remcos—detailing infection chains, persistence and obfuscation techniques, IoCs (domains, file/hash lists, mutexes), infrastructure reuse, and recommended defensive actions to monitor and restrict RMM usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
