logo

AsyncRAT Campaigns Uncovered: How Attackers Abuse ScreenConnect and Open Directories

ID: 5afcadb9-0678-5824-844e-f0103e609561

STIX ID: report--5afcadb9-0678-5824-844e-f0103e609561

Feed Name: Hunt.io Blog

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report documents a sustained 2024–2025 campaign abusing trojanized ConnectWise ScreenConnect and ClickOnce-style installers to deliver AsyncRAT and a custom PowerShell RAT via open directories and phishing redirect chains; it enumerates multiple infrastructure hosts and domains, file- and container-hash IOCs, dual execution paths (in-memory .NET load vs native DLL injection via libPK.dll), aggressive persistence (scheduled tasks), port/TLS-based C2 tradecraft, and provides detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.