الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky warns of a large-scale сampaign using fake free software to deploy a RAT via ScreenConnect

 

 

A remote admin tool ScreenConnect is being distributed through fake websites designed to mimic the official pages of well-known software products. In total, researchers identified more than 90 domains spanning 10 languages, including English, Arabic, Spanish, Chinese, German, Portuguese, and Russian, enabling the attackers to reach a wide range of victims worldwide. The campaign targets both individual users and organizations using Windows.

After detecting an incident through its Managed Detection and Response, Kaspersky uncovered a large-scale campaign in which attackers used fake websites to spread installer archives disguised as popular software, including OBS Studio, DNS Jumper, DS4Windows, Glary Utilities and Bandicam. To drive traffic to these pages, the threat actor also used search engine optimization techniques to place them high in search results.

Across more than 90 identified fraudulent software sites, the same tactic was observed: victims who downloaded what appeared to be legitimate software instead received a hidden ScreenConnect remote administration tool, which gave the attackers persistent access to compromised devices and allowed them to deploy AsyncRAT, an open-source trojan capable of giving them full control over infected systems. Domain registrations linked to this campaign peaked in February 2026; in 2025, the same attacker had used fake websites to disguise malicious installers as games.

 

Example of a website used by attackers to deliver ScreenConnect

Infection occurs through malicious archives containing a legitimate, signed Microsoft file, install.exe, alongside the install.res.1033.dll library. The DLL is loaded onto the device via a DLL sideloading technique and deploys a ScreenConnect service that awaits further instructions from the attackers.

“The campaign targets both users downloading free utilities from the internet and corporate networks, where remote access tools are often allowlisted and granted elevated privileges. Its danger lies in its potential to facilitate large-scale credential theft and unauthorized access to systems, with the stolen data typically later resold on dark web forums,” says Denis Kulik, lead SOC Analyst at Kaspersky.

To mitigate the risks associated with this threat, Kaspersky experts recommends that businesses:

  • Enforce strict software installation controls (application allowlisting, blocking MSI package installations from untrusted sources).
  • Continuously monitor for new remote administration services and scheduled tasks.
  • Filter outbound traffic to unknown domains and IP addresses.
  • Keep your employees informed about relevant threats. Kaspersky Automated Security Awareness Platform helps cultivate cyber-savvy behavior, including safe downloading practices.
  • Verify the authenticity of software sources.
  • Augment existing security controls with human-led detection and global threat intelligence through solutions like Kaspersky Managed Detection and Response (MDR), which offers 24/7 monitoring, detection, investigation and rapid response to sophisticated cyberattacks
  • Monitor credentials for signs of compromise to mitigate risks, as a compromised account or system access can serve as a vector for further attacks on the organization. Kaspersky Digital Footprint Intelligence provides continuous monitoring across open and dark web sources, enabling timely response to potential threats.

Kaspersky experts also recommend users to follow this advice:

  • Be cautious with downloads. Only download software and media from reputable sources. Malicious software can be bundled with legitimate software, especially if downloaded from dubious websites.
  • Use a strong security solution on all devices, such as Kaspersky Premium. It will warn you about potential threats and prevent infection.
  • Enable multi-factor authentication and monitor accounts: Activate two-factor authentication on IDs and financial apps and regularly review statements for unauthorized activity.
  • Check the authenticity of websites. Double-check URL formats and organizations name spellings.

The full report is available on Securelist.com.

 

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Follow us on:

 

 

Related Posts:

Kandima Maldives Brings International Football Talent and a UNDP-Funded Art for Biodiversity Exhibition to its Shores

Bartlett drives Tourism Cooperation with Jamaica and Saudi Fund for Development

Central Bank of Egypt Launches the Fourth Edition of FinTech Got Talent 2026 Competition for University Students

Hyundai Motor Group and African Development Bank Partner to Accelerate Sustainable Development Across Africa

Türkiye’s Black Sea Peaks Welcome Back KAÇKAR BY UTMB 2026 for Second Edition

Dubai Gold District Hotels in Deira Welcome Travelers for Dubai’s Exhibition Season

AHOY and Lumina Partners Forge Strategic Alliance to Deploy Sovereign Physical AI Across Critical Sectors

Kaspersky unveils how the worst cyber incidents hit SMBs over the past year

آخر الأخبار
الرقابة المالية و«الأوروبي لإعادة الإعمار» يبحثان تنشيط البورصة وتعزيز جاذبية القطاع غير المصرفي بنك القاهرة و«تيلدا» يعلنان عن إتاحة ربط بطاقة «تيلدا» بتطبيق «إنستاباي» كأول بطاقة ماستركارد مسبقة ... رئيس الوزراء يتفقد المرحلة الثانية من الأتوبيس الترددي (BRT) الرقابة المالية تبحث مع نائب رئيس البنك الأوروبي تعزيز التعاون لزيادة جاذبية القطاع المالي غير المصر... وزارة الإسكان تواصل طرح فرص استثمارية متنوعة عبر المنصات الرقمية للاستثمار المصري والأجنبي بهيئة الم... بريدفاست تطلق Breadfast Food لتوصيل طلبات المطاعم عبر تطبيق واحد Kandima Maldives Brings International Football Talent and a UNDP-Funded Art for Biodiversity Exhibit... وزير الزراعة ومحافظ البحيرة يشهدان احتفالية عيد الفلاح الـ 74 تحت شعار "أرض مصر تتسع بالعطاء والإنتا... في إطار مشاركة الفلاحين الاحتفال بعيدهم الـ 74، أجرى السيد علاء فاروق، وزير الزراعة واستصلاح الأراضي... TechSource GDS وJob @ يوقعان اتفاقية تعاون لتوفير المواهب التقنية ودعم توسع الشركات الخليجية الرقابة المالية :تخفيف الاشتراطات المطلوبة في مراقبي الحسابات استجابة للواقع العملي ومراعاة للتكاليف بحضور وزير الاتصالات ICT Misr والمعهد القومي للاتصالات يوقّعان بروتوكول تعاون لتدريب الطلاب 3 أسابيع فقط تحسم مبيعات المرحلة الأولى من Walk’n.. «دبي للتطوير العقاري» تراهن على وجهة متكاملة في ... أحمد جمال الدين: إلغاء معرض سيتي سكيب مصر 2026 يؤكد أن السوق أمام مرحلة جديدة لتطوير أدوات التسويق وزيرة الإسكان تتابع موقف مشروعات الصرف الصحي ضمن المبادرة الرئاسية «حياة كريمة» بمحافظات دمياط والمن... أحمد الوكيل يصدر قرارًا بتشكيل اللجنة العامة للتطوير العقاري باتحاد الغرف التجارية برئاسة أحمد شلبي وزير التربية والتعليم يتفقد عددا من مدارس محافظة الغربية ويتابع جاهزية المدارس وانتظام الطلاب وسير ا... وزارة الصحة تنفذ قافلة طبية متخصصة في صحة الفم والأسنان لرعاية المسنين بالمقطم تعزيز التعاون بين جامايكا والصندوق السعودي للتنمية لتطوير مشاريع سياحية جديدة وفد رئاسي من مدغشقر يزور "IDG" لبحث نقل التجربة المصرية في المجمعات الصناعية