Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ScreenConnect leveraged in cyberattacks | Kaspersky official blog

0
Medium
Vulnerabilityweb
Published: 07/29/2026 (07/29/2026, 15:49:29 UTC)
Source: Kaspersky Security Blog

Description

A cyberattack campaign leverages the legitimate remote administration tool ScreenConnect by distributing it through fake websites mimicking popular free software. The attackers use DLL sideloading to silently install ScreenConnect alongside the intended software, then deploy AsyncRAT, a remote access Trojan, to gain unauthorized access. The campaign disables security features like Windows Defender exclusions and User Account Control, and establishes persistence via scheduled tasks. The attackers aim to control enterprise systems for potential resale on cybercrime marketplaces. Kaspersky detects ScreenConnect in this context as a potentially unwanted application and recommends strict application control and network monitoring to defend against such attacks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 16:00:13 UTC

Technical Analysis

This campaign abuses ScreenConnect, a legitimate remote administration utility, by bundling it with fake installers distributed via phishing websites designed to look like official pages for popular free software. The attackers use DLL sideloading to install ScreenConnect without user awareness, then execute malicious scripts to disable security mechanisms (Windows Defender exclusions, UAC) and deploy AsyncRAT. AsyncRAT connects to attacker-controlled command-and-control servers to receive instructions. Persistence is maintained through scheduled Windows tasks. The campaign targets enterprise environments to gain unauthorized access, likely for resale on cybercrime marketplaces. Kaspersky's detection classifies this use of ScreenConnect as not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen. Mitigation includes application allowlisting, monitoring for new remote management tools and scheduled tasks, and filtering outbound traffic to unknown destinations.

Potential Impact

The campaign enables attackers to gain unauthorized remote access to enterprise systems by deploying AsyncRAT through a weaponized ScreenConnect installation. This can lead to data harvesting, lateral movement within networks, and persistent control of compromised machines. Security features such as Windows Defender and User Account Control are disabled or bypassed, increasing the risk of further compromise. The ultimate impact is unauthorized access and potential resale of compromised systems on cybercrime marketplaces.

Mitigation Recommendations

No official patch is applicable since ScreenConnect is a legitimate tool misused by attackers. Organizations should enforce strict application control policies, including software allowlisting and restricting MSI installations from unverified sources. Monitoring for the installation of new remote management utilities and suspicious scheduled tasks is recommended. Outbound network traffic from workstations should be filtered to block connections to unknown IP addresses and domains. Utilizing managed detection and response services, such as Kaspersky MDR, can help detect and respond to such threats. These measures address the specific attack vector described and are aligned with vendor recommendations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/screenconnect-fake-software-campaign/56197/","fetched":true,"fetchedAt":"2026-07-29T16:00:05.753Z","wordCount":1082}

Threat ID: 6a6a23859c2644c7f8b91905

Added to database: 07/29/2026, 16:00:05 UTC

Last enriched: 07/29/2026, 16:00:13 UTC

Last updated: 07/29/2026, 16:00:54 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses