Researchers in cybersecurity have revealed the specifics of a new campaign that uses the legitimate Remote Monitoring and Management (RMM) program ConnectWise ScreenConnect to deliver a fleshless loader that drops the AsyncRAT remote access trojan (RAT) to steal private information from compromised hosts.
After gaining remote access via ScreenConnect, the attacker ran a layered PowerShell loader and VBScript script that retrieved and ran obfuscated components from external URLs. According to a source provided to The Hacker News, LevelBlue stated. Among these were encoded.NET assemblies that eventually unpacked into AsyncRAT while retaining persistence through a fictitious scheduled activity called “Skype Updater.
According to the cybersecurity company’s documentation of the infection chain, the threat actors use a ScreenConnect deployment to establish a remote session read more about AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
