ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software Sites

ScreenConnect Masked as Freeware (TL-2026-1040), also tracked as The SOC Files: ScreenConnect Masked as Freeware, is a high-severity malware campaign, first published 2026-07-01. It has no confirmed attribution, affects ConnectWise ScreenConnect, maps to 34 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 55 indicators of compromise.

Key facts for TL-2026-1040

Threat ID
TL-2026-1040
Also known as
The SOC Files: ScreenConnect Masked as Freeware
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-01
Last reviewed
2026-07-01
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumer, gaming, individual-users, corporate-networks, technology, finance
Target regions
North America, Europe, Asia, Global
Detection rules
9
Indicators of compromise
55

Malware and tooling in ScreenConnect Masked as Freeware

Malware and tooling: AsyncRAT, ScreenConnect

Since October 2025, an unattributed threat actor has run a large-scale SEO-poisoning campaign across 90+ fraudulent, localized websites spoofing 25+ popular free tools (OBS Studio, VLC, DS4Windows, Bandicam, Process Hacker, Glary Utilities, and others) to deliver trojanized ScreenConnect installers bundled with a custom AsyncRAT build. Kaspersky (Securelist) and NCC Group/FOX-IT independently tracked the operation, which uses DLL sideloading, multi-stage VBS/PowerShell/JS droppers, in-memory .NET compilation, process hollowing into RegAsm.exe, UAC bypass, and Defender exclusion tampering to gain stealthy, persistent remote access to both individual users and corporate networks.

How ScreenConnect Masked as Freeware works

The campaign begins with SEO-optimized, hreflang-tagged fake download portals (10+ localized languages: English, Russian, Chinese, German, French, Spanish, Arabic, and others) that impersonate 25+ legitimate freeware titles including OBS Studio, DNS Jumper, DS4Windows, Bandicam, Process Hacker, Glary Utilities, tModLoader, Defender Control, CrosshairX, VLC Media Player, KM Player, and LibreOffice. The pages use fabricated Schema.org ratings and distinct analytics/verification IDs to compartmentalize infrastructure and inflate search-result trust signals.

Victims download an archive containing a legitimate, Microsoft-signed `install.exe` alongside a malicious sideloaded library `install.res.1033.dll`, plus an Assets folder holding both the real requested freeware and a ScreenConnect (ConnectWise) remote-access installer disguised as MSI packages named `vcredist_x64.dll` / `vcredist_x86.dll`. Execution triggers a PowerShell script (`Fj5NmEsp9EuKrun.ps1`) that adds broad Microsoft Defender exclusions (all drives, system directories, RegAsm.exe) and flips the `ConsentPromptBehaviorAdmin` registry value to 0 to silently bypass UAC.

A VBScript dropper (`installer_method3_stream.vbs`) stages further payloads into `C:\Users\Public`, invoking `script.vbs`, which in turn triggers an obfuscated PowerShell stage (`cap.ps1`). That script parses `secret_bytes.txt` for `[SXX-` -tagged byte sequences, XOR-decrypts them (key 0xA7), reverses bit order, and reflectively loads the resulting .NET injector entirely in memory — leaving no dropped executable for static scanners. The in-memory injector performs process hollowing (T1055.012) into a suspended `RegAsm.exe` process to inject a non-stock AsyncRAT build that includes a cryptocurrency clipper, a dynamic runtime plugin-loading framework, and geofencing logic that avoids victims geolocated in the Middle East, North Africa, and Central Asia.

Persistence is established via a Scheduled Task (`MasterPackager.Updater`) that re-launches `script.vbs` every 2 minutes. ScreenConnect is configured against actor-controlled relay infrastructure (domains embedded in `system.config` XML: servermanagemen.xyz, r.manage-server.xyz, manageserver.xyz, winservec.net, cloudsynn.com, pingserv.pro, ehostservers.xyz, serverdnsplan.net), giving the operator an independent, dual-use legitimate RMM channel into the host alongside AsyncRAT's C2 (primary observed: mora1987.work.gd). Fake-software hosting is split across at least three infrastructure clusters (Dynu Systems/US, NOHAVPS LLC/US, dataforest GmbH/Germany), consistent with deliberate compartmentalization to survive partial takedowns. NCC Group and FOX-IT, working a related spike in ScreenConnect alerts, scoped a parallel/overlapping SEO-poisoning operation using the same ScreenConnect-abuse pattern to deploy a GPU cryptojacking payload, indicating the underlying distribution infrastructure/tooling is being reused or shared across multiple monetization payloads (AsyncRAT + cryptominer).

MITRE ATT&CK techniques used in TL-2026-1040

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Privilege Escalation

T1055.012 Process Hollowing; T1548.002 Bypass User Account Control

Collection

T1056.001 Keylogging; T1115 Clipboard Data

Execution

T1059.001 PowerShell; T1059.005 Visual Basic; T1059.007 JavaScript; T1204.002 Malicious File; T1569.002 Service Execution

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1614.001 System Language Discovery

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Initial Access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

stealth

T1202 Indirect Command Execution; T1574.001 DLL

command-and-control

T1219 Remote Access Tools

Impact

T1496 Resource Hijacking

Resource Development

T1583.001 Domains; T1587.001 Malware; T1588.002 Tool

Affected products and versions in ScreenConnect Masked as Freeware

  • ConnectWise — ScreenConnect
    Vulnerable versions: all versions abused as trojanized installer payload
  • Microsoft — Windows (RegAsm.exe / Windows Script Host / Defender)
    Vulnerable versions: all supported Windows versions

Remediation for ScreenConnect Masked as Freeware

Immediate actions

  • Block IOC domains and IPs at DNS/proxy/firewall layer (servermanagemen.xyz, r.manage-server.xyz, manageserver.xyz, winservec.net, cloudsynn.com, pingserv.pro, ehostservers.xyz, serverdnsplan.net, mora1987.work.gd, studioobs.com, fileget.loseyourip.com, direct-download.giize.com)
  • Hunt for scheduled task named MasterPackager.Updater across the fleet and remove it
  • Hunt for RegAsm.exe processes with anomalous parent processes or network connections and terminate/isolate affected hosts
  • Audit Microsoft Defender exclusion lists for unauthorized entries covering entire drives, system directories, or RegAsm.exe
  • Alert on unauthorized ScreenConnect (ConnectWise) client installations and validate system.config relay hostnames against an approved allowlist
  • Block execution of user-downloaded VBScript/WSH content by default (WSH restriction policy or AppLocker)

Workarounds

  • Disable WSH (Windows Script Host) execution for standard users where operationally feasible
  • Restrict local admin rights to reduce UAC-bypass impact

Longer-term hardening

  • Deploy EDR with behavioral detection for process hollowing / reflective PE loading into RegAsm.exe and similar .NET utility processes
  • Implement application control (AppLocker/WDAC) to restrict unsigned or newly-downloaded installers from execution
  • Enforce a corporate policy restricting or monitoring installation of remote-management/RMM tools (ScreenConnect, AnyDesk, etc.) outside IT-sanctioned channels
  • Deploy DNS-layer web filtering with category blocking for newly-registered and SEO-anomalous domains
  • User awareness training on verifying official download sources for freeware utilities rather than trusting search-engine ranking

Timeline of ScreenConnect Masked as Freeware

  • Campaign activity begins; earliest observed fraudulent freeware landing pages and trojanized ScreenConnect/AsyncRAT distribution.
  • Early public reporting on ScreenConnect abuse to deliver AsyncRAT and SectopRAT on Windows systems.
  • Security Affairs and other outlets report on ConnectWise ScreenConnect abuse to drop AsyncRAT.
  • NCC Group, working jointly with FOX-IT following a spike in ScreenConnect-related client alerts, identifies the full scope of an overlapping SEO-poisoning campaign abusing the same distribution pattern for a GPU cryptojacking payload.
  • Primary AsyncRAT distribution activity via the tracked infrastructure appears to pause, per Securelist's observation window (October 2025 - March 2026).
  • Independent AsyncRAT malware analysis (MITRE ATT&CK mapping, IOCs, detection guidance) published by zerosday.
  • Multiple outlets (GBHackers, Cybersecurity News, Cryptika, CyberPress) report a related/overlapping SEO-poisoning campaign impersonating 25+ popular apps to deliver AsyncRAT since October 2025.
  • Microsoft Security Blog publishes analysis of a cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities via poisoned search results, describing infrastructure and TTP overlap with the AsyncRAT distribution campaign.
  • Follow-up threat campaign analysis describes the GPU-targeted cryptojacking campaign extending SEO poisoning to AI chatbot results and deploying persistent ScreenConnect backdoors.
  • Kaspersky Securelist publishes 'The SOC Files: ScreenConnect masked as freeware,' a detailed inside look with full technical chain, infrastructure clusters, hashes, and 90+ domain count; many landing pages still live at time of publication.

Sources cited for ScreenConnect Masked as Freeware

Threats related to ScreenConnect Masked as Freeware

Detection coverage for TL-2026-1040

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1040 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats