logo

Masquerade: You Downloaded ScreenConnect not Grok AI!

ID: ece62502-ac4a-57ac-a54f-97a34bbe3a05

STIX ID: report--ece62502-ac4a-57ac-a54f-97a34bbe3a05

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-07-28

Date Updated: 2026-08-03

ADMIRALTY:B6
...
...

**Executive summary:** NCC Group DFIR investigated a drive-by compromise originating from a malicious Facebook advert that installed ScreenConnect (used for persistence and file transfer) and delivered an obfuscated multi-stage payload resulting in AsyncRAT deployment; the attackers harvested browser data and keystrokes and communicated with C2 185.149.232.197:56001. IOCs include domains (canvadreamlab.xyz, authenticate-meta.com, jtsec.innocreed.com, openaigrok.com), IPs (194.26.192.107, 185.149.232.197) and SHA1 hashes for key payloads, and the report includes recommended mitigations such as disabling browser autofill and using password managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.