SEO Poisoning Attack Uses Microsoft Binary to Install RMM Tool
ID: f7c98c31-8126-5080-9686-a973f8501a94
STIX ID: report--f7c98c31-8126-5080-9686-a973f8501a94
Feed Name: GBHackers
A search‑engine poisoning campaign is distributing a fake TestDisk installer (testdisk-7.3.exe) that is actually a Microsoft-signed setup binary used to sideload a malicious autorun.dll; the payload installs a legitimate TestDisk alongside a trojanized ScreenConnect RMM client that gives attackers hands‑on remote access. The report includes IOCs (testdisk.dev, direct-download.gleeze.com, IP 193.42.11.108, SHA‑256 1b2555b09ac62164638f47c8272beb6b0f97186e37d3a54cb84c723ff7a2eee5) and recommends monitoring these artifacts, hunting for unsigned/unusual DLLs loaded by signed binaries, and allow‑listing/alerting on ScreenConnect infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
