BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AsyncRAT Delivered via ScreenConnect in New Fileless Attack Campaign

Hackers Abuse ScreenConnect in Fileless AsyncRAT Campaign to Steal Credentials and Crypto Data

  • Certain threat actors are misusing ConnectWise ScreenConnect, a legitimate remote monitoring tool, to access target systems and deploy Malware.
  • Cybersecurity researchers observed attackers delivering AsyncRAT, a remote access trojan, using fileless malware techniques to steal sensitive data.
  • Initial access was achieved by sending fraudulent ScreenConnect installers disguised as business documents in phishing emails.
  • The campaign uses complex scripts and scheduled tasks to maintain presence on infected machines and evade detection.
  • Stolen data, including credentials and information on crypto wallets, is sent to a remote server controlled by the attackers.

Attackers are exploiting ConnectWise ScreenConnect to gain unauthorized access to computers as part of a new campaign, according to findings published by cybersecurity researchers on September 11, 2025. The goal is to deliver a remote access trojan called AsyncRAT in order to steal data from compromised devices.

- Advertisement -

Analysts at LevelBlue reported that the attackers use phishing emails containing malicious ScreenConnect installers that appear to be financial or business-related files. After establishing remote access, the attackers manually deploy a series of scripts and software components without leaving obvious files on the system’s disk, making detection much more difficult.

According to an official report from LevelBlue, the attackers run a layered Visual Basic Script and PowerShell loader. “The attacker used ScreenConnect to gain remote access, then executed a layered VBScript and PowerShell loader that fetched and ran obfuscated components from external URLs,” the researchers said. The process ultimately unpacks AsyncRAT and maintains ongoing access by setting up a fake “Skype Updater” task.

The malware retrieves two main files—“logs.ldk” and “logs.ldr”—from an attacker-controlled server. The first file writes a new script for persistent access, while the second is used to launch AsyncRAT. This trojan sends user keystrokes, browser logins, and details of installed cryptocurrency wallet applications (like those used in Chrome, Brave, Edge, Opera, and Firefox) back to a command-and-control server.

All communication and stolen data are sent over a direct internet connection to the attackers’ remote server, with configuration details either built into the code or loaded from a remote Pastebin page. The researchers explained that fileless malware, which operates in a computer’s memory instead of saving files on disk, is especially difficult to detect and remove.

- Advertisement -

The technique relies on trusted system tools and remote access programs, highlighting the challenges that organizations face in defending against fileless malware attacks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor: Strategy’s STRC volatility below S&P 500 ETF at 9%

Strategy's STRC preferred stock posted 30-day historical volatility of 9%, below the SPDR S&P...

MI5 Warns 100+ UK Academics Aided China Spy AI Research

MI5 issued an unprecedented alert warning over 100 U.K.-linked academics contributed to research funded...

Trump to host gala for top TRUMP meme coin holders Nov. 22

The top 185 TRUMP meme coin holders will attend a Nov. 22 GALA dinner...

Bitcoin Needs $87.5K Weekly Close to Rally, Risks $80K Drop

Glassnode reports that Bitcoin investors who bought during last year's rally are selling more...

NEAR Intents recovers $3.8M after ultimatum to exploiter

NEAR Intents recovered the full $3.8 million stolen in a security breach.The exploiter returned...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading