logo

SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025

ID: 30da23d5-cf5e-5e8a-897a-b5fe2e290ad2

STIX ID: report--30da23d5-cf5e-5e8a-897a-b5fe2e290ad2

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A long-running SEO poisoning campaign (Oct 2025–Mar 2026) pushed fake download pages for popular Windows apps to deliver trojanized installers that sideload a malicious libvlc.dll, install a hidden MSI that deploys ScreenConnect, and ultimately inject AsyncRAT via in-memory techniques; the RAT includes keylogging, clipboard monitoring, a 16‑currency crypto clipper, dynamic plugins, region-based geo-fencing, and multiple persistence mechanisms, with infrastructure using randomized download tokens and over 100 malicious files observed on VirusTotal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.