ScreenConnect Malware Campaign Uses SEO Poisoning to Target Freeware Downloads

A massive, multi-language malware campaign that exploits the legitimate remote administration tool ScreenConnect.

The threat actors employ sophisticated search engine optimization (SEO) poisoning to push malicious websites to the top of Google and Bing search results, tricking users into downloading what appears to be legitimate freeware.

This highly coordinated attack ultimately deploys the AsyncRAT remote access trojan, allowing the attackers to maintain persistent, remote control over compromised systems to harvest sensitive data.

According to reports from IntCyberDigest and Kaspersky, this widespread threat initially surfaced in late 2025. It escalated through early 2026, targeting both corporate networks and individual users worldwide.

SEO Poisoning Spreads ScreenConnect

The core of this operation relies on an expansive infrastructure of more than 90 spoofed domains hosted on servers across the United States and Germany.

These malicious websites accurately mimic the official download portals for popular open-source and freeware applications, such as OBS Studio, DS4Windows, Process Hacker, and DNS Jumper.

ScreenConnect service execution event with suspicious parameters (Source: securelist)
ScreenConnect service execution event with suspicious parameters (Source: securelist)

The attackers use SEO poisoning tactics to ensure their fake domains rank highly in organic search results, increasing the likelihood that an unsuspecting user will click their links instead of genuine vendor sites.

The landing pages are localized into multiple languages, including English, Russian, Chinese, German, Spanish, and Arabic, indicating a broad, international targeting strategy.

When a user downloads a compromised installer from one of these fake sites, they receive an archive containing a legitimate, digitally signed Microsoft execution binary alongside a malicious library file.

Snippet of Fj5NmEsp9EuKrun.ps1 (Source: securelist)
Snippet of Fj5NmEsp9EuKrun.ps1 (Source: securelist)

The deployment mechanism leverages a technique known as DLL sideloading. The primary executable unknowingly loads the malicious DLL, which silently installs a customized version of the ScreenConnect service in the background.

To maintain the illusion of legitimacy, the requested freeware application is still installed and presented to the user via a standard graphical interface.

This dual-action approach ensures the victim remains unaware that their system has been compromised, as the expected software functions normally.

Securelist said, once the ScreenConnect service is active, it operates with administrative privileges, executing a series of obfuscated PowerShell and VBScript files to establish persistence and evade detection.

The malware specifically configures Microsoft Defender exclusions for the entire C:\ drive and turns off User Account Control (UAC) prompts.

Indicators of Compromise

TypeIndicatorDescription
Domainmora1987[.]work[.]gdAsyncRAT C2 server domain
URLhxxps[:]//fileget.loseyourip[.]com/obs-studio-windows-full/gVOMs5VZ9BtlcaMMalicious OBS Studio installer download link
URLhxxps[:]//direct-download.giize[.]com/dns-jumper/iopbsr4hymbo7nfa1q7jMalicious DNS Jumper installer download link

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories