Acronis Cyberthreats Update, July 2025
ID: dd253394-454e-5d2b-b9c1-21993d790d4b
STIX ID: report--dd253394-454e-5d2b-b9c1-21993d790d4b
Feed Name: TRU Security by Acronis
Acronis TRU reports that attackers are using “Authenticode stuffing” to modify signed installers (notably ConnectWise ScreenConnect and SonicWall NetExtender) so they remain signature-valid while redirecting to attacker-controlled configurations; these trojanized installers have been distributed in phishing campaigns, install backdoors (showing a fake Windows Update) and in some cases steal credentials. The update also notes a rise in malware detections (over 980k blocks in June) and recommends inspecting configuration data in signed binaries and limiting remote access tool usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
