A massive, multi-language malware campaign that exploits the legitimate remote administration tool ScreenConnect.
The threat actors employ sophisticated search engine optimization (SEO) poisoning to push malicious websites to the top of Google and Bing search results, tricking users into downloading what appears to be legitimate freeware.
This highly coordinated attack ultimately deploys the AsyncRAT remote access trojan, allowing the attackers to maintain persistent, remote control over compromised systems to harvest sensitive data.
According to reports from IntCyberDigest and Kaspersky, this widespread threat initially surfaced in late 2025. It escalated through early 2026, targeting both corporate networks and individual users worldwide.
SEO Poisoning Spreads ScreenConnect
The core of this operation relies on an expansive infrastructure of more than 90 spoofed domains hosted on servers across the United States and Germany.
These malicious websites accurately mimic the official download portals for popular open-source and freeware applications, such as OBS Studio, DS4Windows, Process Hacker, and DNS Jumper.

The attackers use SEO poisoning tactics to ensure their fake domains rank highly in organic search results, increasing the likelihood that an unsuspecting user will click their links instead of genuine vendor sites.
The landing pages are localized into multiple languages, including English, Russian, Chinese, German, Spanish, and Arabic, indicating a broad, international targeting strategy.
When a user downloads a compromised installer from one of these fake sites, they receive an archive containing a legitimate, digitally signed Microsoft execution binary alongside a malicious library file.

The deployment mechanism leverages a technique known as DLL sideloading. The primary executable unknowingly loads the malicious DLL, which silently installs a customized version of the ScreenConnect service in the background.
To maintain the illusion of legitimacy, the requested freeware application is still installed and presented to the user via a standard graphical interface.
This dual-action approach ensures the victim remains unaware that their system has been compromised, as the expected software functions normally.
Securelist said, once the ScreenConnect service is active, it operates with administrative privileges, executing a series of obfuscated PowerShell and VBScript files to establish persistence and evade detection.
The malware specifically configures Microsoft Defender exclusions for the entire C:\ drive and turns off User Account Control (UAC) prompts.
Indicators of Compromise
| Type | Indicator | Description |
|---|---|---|
| Domain | mora1987[.]work[.]gd | AsyncRAT C2 server domain |
| URL | hxxps[:]//fileget.loseyourip[.]com/obs-studio-windows-full/gVOMs5VZ9BtlcaM | Malicious OBS Studio installer download link |
| URL | hxxps[:]//direct-download.giize[.]com/dns-jumper/iopbsr4hymbo7nfa1q7j | Malicious DNS Jumper installer download link |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.