logo

Trojanized ScreenConnect installers evolve, dropping multiple RATs on a single machine

ID: d7de1861-55df-5f58-8b47-caaf51ca0d8c

STIX ID: report--d7de1861-55df-5f58-8b47-caaf51ca0d8c

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2025-09-03

Date Updated: 2026-07-24

...
...

**Executive summary:** Acronis TRU reports an increase since March 2025 in campaigns abusing trojanized ConnectWise ScreenConnect installers (now using evasive ClickOnce runners) to establish access in U.S. networks and rapidly deploy multiple RATs—including AsyncRAT, a custom PowerShell RAT, PureHVNC and Remcos—detailing infection chains, persistence and obfuscation techniques, IoCs (domains, file/hash lists, mutexes), infrastructure reuse, and recommended defensive actions to monitor and restrict RMM usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.