logo

SEO Poisoning Campaign Uses Fake Popular Apps to Deliver AsyncRAT

ID: f9f2f832-a4a0-539e-9f60-bddfaf870cd5

STIX ID: report--f9f2f832-a4a0-539e-9f60-bddfaf870cd5

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Executive summary: A persistent SEO poisoning campaign (active since at least October 2025) lures users searching for popular applications to fake download portals that bundle legitimate installers with malicious DLLs, enabling DLL sideloading and deployment of AsyncRAT via a preconfigured ScreenConnect foothold; the AsyncRAT build contains a cryptocurrency clipper, a plugin framework, geo-fencing, and multiple C2 endpoints, while the operator uses tokenized delivery URLs and SEO tuning to evade detection. Investigators (FOX-IT and NCC Group) identified lure domains, delivery backends, and C2 hosts and recommend monitoring for suspicious ScreenConnect installs, DLL sideloading, access to known lure/delivery domains, and full incident response for confirmed compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.