RST TI Report Digest: 06 Jul 2026
ID: 21dea12f-a964-541f-82d7-cee2adcf4f7d
STIX ID: report--21dea12f-a964-541f-82d7-cee2adcf4f7d
Feed Name: RST Cloud Blog
**Executive summary:** Researchers uncovered a large-scale campaign that abuses legitimate ScreenConnect remote-access installers and typosquatted download sites to sideload and inject AsyncRAT (via DLL sideloading and process hollowing), establish persistence with scheduled tasks, and connect to clustered C2 infrastructure — the report provides extensive IOCs (IPs, ~90+ typosquatted domains, URLs, and multiple file hashes) and notes likely credential theft and ongoing remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
