The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
ID: 27796bfe-ce5f-5f19-ba64-8b20b315384a
STIX ID: report--27796bfe-ce5f-5f19-ba64-8b20b315384a
Feed Name: Securelist by Kaspersky
Kaspersky investigated a global campaign (Oct 2025–Mar 2026) that distributed a hidden ScreenConnect remote administration service and deployed AsyncRAT by luring users to typosquatted/SEO-poisoned download sites for popular freeware; the installers used a Microsoft-signed executable with a malicious DLL (install.res.1033.dll) for DLL sideloading, then executed reflective loading and process hollowing, disabled Defender/UAC, created scheduled-task persistence, and connected to multiple C2 domains. The report maps dozens of spoofed domains and IP clusters, provides IoCs (files, hashes, domains), and supplies SIEM/EDR detection rules and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
