ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software Sites
ScreenConnect Masked as Freeware (TL-2026-1040), also tracked as The SOC Files: ScreenConnect Masked as Freeware, is a high-severity malware campaign, first published 2026-07-01. It has no confirmed attribution, affects ConnectWise ScreenConnect, maps to 34 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 55 indicators of compromise.
Key facts for TL-2026-1040
- Threat ID
- TL-2026-1040
- Also known as
- The SOC Files: ScreenConnect Masked as Freeware
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-01
- Last reviewed
- 2026-07-01
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumer, gaming, individual-users, corporate-networks, technology, finance
- Target regions
- North America, Europe, Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 55
Malware and tooling in ScreenConnect Masked as Freeware
Malware and tooling: AsyncRAT, ScreenConnect
Since October 2025, an unattributed threat actor has run a large-scale SEO-poisoning campaign across 90+ fraudulent, localized websites spoofing 25+ popular free tools (OBS Studio, VLC, DS4Windows, Bandicam, Process Hacker, Glary Utilities, and others) to deliver trojanized ScreenConnect installers bundled with a custom AsyncRAT build. Kaspersky (Securelist) and NCC Group/FOX-IT independently tracked the operation, which uses DLL sideloading, multi-stage VBS/PowerShell/JS droppers, in-memory .NET compilation, process hollowing into RegAsm.exe, UAC bypass, and Defender exclusion tampering to gain stealthy, persistent remote access to both individual users and corporate networks.
How ScreenConnect Masked as Freeware works
The campaign begins with SEO-optimized, hreflang-tagged fake download portals (10+ localized languages: English, Russian, Chinese, German, French, Spanish, Arabic, and others) that impersonate 25+ legitimate freeware titles including OBS Studio, DNS Jumper, DS4Windows, Bandicam, Process Hacker, Glary Utilities, tModLoader, Defender Control, CrosshairX, VLC Media Player, KM Player, and LibreOffice. The pages use fabricated Schema.org ratings and distinct analytics/verification IDs to compartmentalize infrastructure and inflate search-result trust signals.
Victims download an archive containing a legitimate, Microsoft-signed `install.exe` alongside a malicious sideloaded library `install.res.1033.dll`, plus an Assets folder holding both the real requested freeware and a ScreenConnect (ConnectWise) remote-access installer disguised as MSI packages named `vcredist_x64.dll` / `vcredist_x86.dll`. Execution triggers a PowerShell script (`Fj5NmEsp9EuKrun.ps1`) that adds broad Microsoft Defender exclusions (all drives, system directories, RegAsm.exe) and flips the `ConsentPromptBehaviorAdmin` registry value to 0 to silently bypass UAC.
A VBScript dropper (`installer_method3_stream.vbs`) stages further payloads into `C:\Users\Public`, invoking `script.vbs`, which in turn triggers an obfuscated PowerShell stage (`cap.ps1`). That script parses `secret_bytes.txt` for `[SXX-` -tagged byte sequences, XOR-decrypts them (key 0xA7), reverses bit order, and reflectively loads the resulting .NET injector entirely in memory — leaving no dropped executable for static scanners. The in-memory injector performs process hollowing (T1055.012) into a suspended `RegAsm.exe` process to inject a non-stock AsyncRAT build that includes a cryptocurrency clipper, a dynamic runtime plugin-loading framework, and geofencing logic that avoids victims geolocated in the Middle East, North Africa, and Central Asia.
Persistence is established via a Scheduled Task (`MasterPackager.Updater`) that re-launches `script.vbs` every 2 minutes. ScreenConnect is configured against actor-controlled relay infrastructure (domains embedded in `system.config` XML: servermanagemen.xyz, r.manage-server.xyz, manageserver.xyz, winservec.net, cloudsynn.com, pingserv.pro, ehostservers.xyz, serverdnsplan.net), giving the operator an independent, dual-use legitimate RMM channel into the host alongside AsyncRAT's C2 (primary observed: mora1987.work.gd). Fake-software hosting is split across at least three infrastructure clusters (Dynu Systems/US, NOHAVPS LLC/US, dataforest GmbH/Germany), consistent with deliberate compartmentalization to survive partial takedowns. NCC Group and FOX-IT, working a related spike in ScreenConnect alerts, scoped a parallel/overlapping SEO-poisoning operation using the same ScreenConnect-abuse pattern to deploy a GPU cryptojacking payload, indicating the underlying distribution infrastructure/tooling is being reused or shared across multiple monetization payloads (AsyncRAT + cryptominer).
MITRE ATT&CK techniques used in TL-2026-1040
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Privilege Escalation
T1055.012 Process Hollowing; T1548.002 Bypass User Account Control
Collection
T1056.001 Keylogging; T1115 Clipboard Data
Execution
T1059.001 PowerShell; T1059.005 Visual Basic; T1059.007 JavaScript; T1204.002 Malicious File; T1569.002 Service Execution
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1614.001 System Language Discovery
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Initial Access
T1189 Drive-by Compromise; T1566.002 Spearphishing Link
stealth
T1202 Indirect Command Execution; T1574.001 DLL
command-and-control
Impact
Resource Development
Affected products and versions in ScreenConnect Masked as Freeware
- ConnectWise — ScreenConnect
Vulnerable versions: all versions abused as trojanized installer payload - Microsoft — Windows (RegAsm.exe / Windows Script Host / Defender)
Vulnerable versions: all supported Windows versions
Remediation for ScreenConnect Masked as Freeware
Immediate actions
- Block IOC domains and IPs at DNS/proxy/firewall layer (servermanagemen.xyz, r.manage-server.xyz, manageserver.xyz, winservec.net, cloudsynn.com, pingserv.pro, ehostservers.xyz, serverdnsplan.net, mora1987.work.gd, studioobs.com, fileget.loseyourip.com, direct-download.giize.com)
- Hunt for scheduled task named MasterPackager.Updater across the fleet and remove it
- Hunt for RegAsm.exe processes with anomalous parent processes or network connections and terminate/isolate affected hosts
- Audit Microsoft Defender exclusion lists for unauthorized entries covering entire drives, system directories, or RegAsm.exe
- Alert on unauthorized ScreenConnect (ConnectWise) client installations and validate system.config relay hostnames against an approved allowlist
- Block execution of user-downloaded VBScript/WSH content by default (WSH restriction policy or AppLocker)
Workarounds
- Disable WSH (Windows Script Host) execution for standard users where operationally feasible
- Restrict local admin rights to reduce UAC-bypass impact
Longer-term hardening
- Deploy EDR with behavioral detection for process hollowing / reflective PE loading into RegAsm.exe and similar .NET utility processes
- Implement application control (AppLocker/WDAC) to restrict unsigned or newly-downloaded installers from execution
- Enforce a corporate policy restricting or monitoring installation of remote-management/RMM tools (ScreenConnect, AnyDesk, etc.) outside IT-sanctioned channels
- Deploy DNS-layer web filtering with category blocking for newly-registered and SEO-anomalous domains
- User awareness training on verifying official download sources for freeware utilities rather than trusting search-engine ranking
Timeline of ScreenConnect Masked as Freeware
- Campaign activity begins; earliest observed fraudulent freeware landing pages and trojanized ScreenConnect/AsyncRAT distribution.
- Early public reporting on ScreenConnect abuse to deliver AsyncRAT and SectopRAT on Windows systems.
- Security Affairs and other outlets report on ConnectWise ScreenConnect abuse to drop AsyncRAT.
- NCC Group, working jointly with FOX-IT following a spike in ScreenConnect-related client alerts, identifies the full scope of an overlapping SEO-poisoning campaign abusing the same distribution pattern for a GPU cryptojacking payload.
- Primary AsyncRAT distribution activity via the tracked infrastructure appears to pause, per Securelist's observation window (October 2025 - March 2026).
- Independent AsyncRAT malware analysis (MITRE ATT&CK mapping, IOCs, detection guidance) published by zerosday.
- Multiple outlets (GBHackers, Cybersecurity News, Cryptika, CyberPress) report a related/overlapping SEO-poisoning campaign impersonating 25+ popular apps to deliver AsyncRAT since October 2025.
- Microsoft Security Blog publishes analysis of a cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities via poisoned search results, describing infrastructure and TTP overlap with the AsyncRAT distribution campaign.
- Follow-up threat campaign analysis describes the GPU-targeted cryptojacking campaign extending SEO poisoning to AI chatbot results and deploying persistent ScreenConnect backdoors.
- Kaspersky Securelist publishes 'The SOC Files: ScreenConnect masked as freeware,' a detailed inside look with full technical chain, infrastructure clusters, hashes, and 90+ domain count; many landing pages still live at time of publication.
Sources cited for ScreenConnect Masked as Freeware
- The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
- SEO Poisoning Campaign Uses Fake Popular Apps to Deliver AsyncRAT
- From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
- SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025
- SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025
- SEO Poisoning Campaign Impersonates 2025 Popular Apps To Spread AsyncRAT
- SEO Poisoning Leads to ScreenConnect Cryptojacking
- GPU-Targeted Cryptojacking Campaign Extends SEO Poisoning to AI Chatbots, Deploys Persistent ScreenConnect Backdoors
- Hackers Deploy AsyncRAT and SectopRAT Malware Using ScreenConnect on Windows
- Attackers abuse ConnectWise ScreenConnect to drop AsyncRAT
- ASYNCRAT Malware Analysis: MITRE ATT&CK, IOCs & Detection
- AsyncRAT Malware: Analysis, Detection, Removal
- AsyncRAT C2 Framework: Overview, Technical Analysis & Detection
- AsyncRAT Crusade: Detections and Defense
Threats related to ScreenConnect Masked as Freeware
- AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access (SEO-Poisoned Fake Installer Sites)
- Remcos RAT: Technical Analysis of Windows Remote Access Trojan Operations
- GPU-Targeted Cryptojacking Campaign — SEO + AI Chatbot Poisoning Delivers ScreenConnect & SimpleRunPE Process Hollowing into .NET Utilities (Microsoft Defender Experts)
- TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain
- Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org, 36-domain cluster)
- SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)
Detection coverage for TL-2026-1040
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1040 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.