How a single ScreenConnect incident exposed a massive campaign一次ScreenConnect事件如何揭露了一场大规模的攻击
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.

updated UPD 03 Jul 2026
Initial incident investigation
How ScreenConnect entered the system
Expanding the investigation
Fake domain infrastructure
Cluster 1: 162.216.241[.]242 and 198.23.185[.]81
Cluster 2: 2.59.134[.]97
C2 infrastructure analysis
Detection by Kaspersky solutions
Indicators of compromise
Malicious library: install.res.1033.dll
Fake websites addresses
UPD 03.07.2026 : added a package of rules and recommendations that help detect the described malicious activity for companies using our Kaspersky SIEM system.
To access compromised systems, threat actors frequently abuse legitimate remote monitoring tools. At first glance, these utilities rarely raise red flags: they are signed with valid digital certificates, often allowlisted under corporate IT policies, and fully supported by OS vendors. However, they grant attackers the ability to harvest data from target devices, drop malware, and move laterally across the network.
During a recent investigation engagement, the Kaspersky Managed Detection and Response (MDR) team discovered the ScreenConnect remote access tool being leveraged to deploy and execute an AsyncRAT payload.
A deep dive into this single incident unraveled a massive campaign distributing malicious installer archives hosted on spoofed websites. These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, Bandicam, and others. In total, we uncovered more than 90 domain names localized across 10 languages. The malicious archives bundle a legitimate, signed Microsoft install.exe binary alongside a rogue install.res.1033.dll library. It is loaded onto the device via DLL sideloading and deploys the ScreenConnect service, which awaits further instructions from the threat actors.
As a result, what initially appeared to be an isolated ScreenConnect incident served as the starting point for a full investigation into the threat actor’s C2 infrastructure. Every spoofed site we uncovered followed the exact same playbook: dropping a hidden ScreenConnect remote administration service under the guise of a legitimate software installer. This allowed the attackers to maintain control over compromised endpoints, with victims ranging from individual users to organizations.
We continue to break down complex, multi-stage incidents like this in our ongoing The SOC Files series . In this post, we take a deep dive into the technical execution of the ScreenConnect attack and analyze the broader infrastructure under the threat actor’s control.
The investigation was triggered by an alert from Kaspersky MDR, which flagged the creation and execution of suspicious PowerShell and VBS scripts spawned by a ScreenConnect process.
ScreenConnect is a legitimate remote management utility. Kaspersky solutions detect it as not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen.
ScreenConnect was running as an Access-type service — enabling direct remote connectivity — with the server explicitly passed via the command line:
ScreenConnect service execution event with suspicious parameters
Once running, ScreenConnect created and executed a PowerShell script named Fj5NmEsp9EuKrun.ps1 :
Malicious PowerShell script creation
Below is an excerpt from the contents of the script:
Snippet of Fj5NmEsp9EuKrun.ps1
This script configures Microsoft Defender exclusions for the following objects:
All disks in the system: C:\, D:\, and others
All root directories on the C:\ drive, as well as the C:\Users\Public directory
Additionally, the script disables User Account Control (UAC) prompts by setting the ConsentPromptBehaviorAdmin registry parameter to 0.
Following this setup, the ScreenConnect service goes on to create a VBScript file:
Malicious VBScript creation
The installer_method3_stream.vbs script creates five files in the C:\Users\Public directory ( msgbox.txt , secret_bytes.txt , 1.vb , cap.ps1 , and script.vbs ) and immediately triggers their execution by launching script.vbs .
Contents of script.vbs
This script terminates all active powershell.exe processes to cover its tracks and executes cap.ps1 in a hidden window.
cap.ps1 reads the contents of the secret_bytes.txt file, extracts sequences matching the [SXX- pattern, and converts XX from hexadecimal representation to a byte. It then uses a 0xA7 XOR key to decrypt each byte and inverts the bit order. The resulting byte array yields a fully formed PE binary, which is then reflectively loaded into the CLR.
Within the loaded assembly, the ConsoleApp1.Module1 type contains a static method named Run . The script uses reflection ( Reflection.BindingFlags ) to resolve a reference to this method and invoke it.
The Run method executes a process hollowing technique ( T1055.012 ), spawning a new RegAsm.exe process with the CREATE_SUSPENDED flag. The deobfuscated and decrypted PE image from secret_bytes.txt is then copied into its address space. As a result, the RegAsm.exe process no longer executes its original code, instead serving as a container for the injected .NET module — which, in this case, is the AsyncRAT remote access Trojan.
To establish persistence, the malware schedules a task named MasterPackager.Updater:
This task triggers every two minutes, ensuring that script.vbs — and consequently the entire loader chain — executes even after a system reboot.
Once the entire infection chain successfully executes, the RegAsm.exe process establishes a connection to the C2 domain mora1987[.]work[.]gd .
AsyncRAT infection and persistence chain via ScreenConnect
A retrospective analysis of the incident allowed us to pinpoint the source of the ScreenConnect installation: a user-downloaded archive named obs-studio-windows-x64.zip .
The archive was downloaded from hxxps://www.studioobs[.]com/ , a typosquatted domain mimicking the official site for OBS Studio, a popular open-source screen recording app. This site is present in search engine results; in this specific incident, the user landed on the malicious domain directly from a search query, a vector we analyze in more detail below.
Clicking the download button for the supposedly legitimate software triggers a request to the following URL, from which the archive is fetched:
Site used to deliver ScreenConnect
The archive contains a legitimate, Microsoft-signed executable named install.exe (87603EA025623B19954E460ADD532048), renamed to masquerade as the OBS Studio installer, along with a malicious library named install.res.1033.dll . Additionally, the archive includes an Assets folder containing both a copy of the actual software being impersonated and the ScreenConnect utility.
Contents of obs-studio-windows-x64.zip
The complete file structure of the archive is organized as follows:
Detailed directory tree of obs-studio-windows-x64.zip
When OBS-Studio-Installer.exe is executed, it loads install.res.1033.dll via DLL sideloading. This library contains the instructions required to install both ScreenConnect and OBS Studio. The deployment relies on native Windows utilities ( msiexec.exe ), but the attackers renamed the standard MSI packages to look like DLL files:
Assets\x86\Data\vcredist_x64.dll : ScreenConnect installer
Assets\x86\Data\vcredist_x86.dll : OBS Studio installer
The contents of the vcredist_x64.dll MSI package are shown below:
ScreenConnect installation files
The Windows Installer is launched to install ScreenConnect silently in the background without requiring a system reboot:
Once the installation wraps up, a new service named Microsoft Update Service is created. The command line for this service explicitly defines the connection server as r[.]servermanagemen[.]xyz .
Meanwhile, the MSI package for the actual OBS Studio software runs using a standard graphical user interface.
ScreenConnect and OBS Studio installation workflow
The attackers’ reliance on the legitimate install.exe binary provided a crucial pivot point for our broader investigation. We discovered that this specific file was being deployed in the wild under a variety of suspicious aliases, including:
crosshairx_installer.exe
obs-studio-installer.exe
glary utilities pro.exe
processhacker-2.39-setup.exe
These file names indicate that the threat actor was disguising their ScreenConnect archives as popular utilities beyond OBS Studio. Among the fakes, we identified counterfeit installers for DS4Windows, DNS Jumper, Glary Utilities, and Process Hacker. Crucially, when we search for these utilities on major search engines, these fraudulent sites frequently appear at the very top of the organic search results. This indicates that the threat actor is actively leveraging SEO techniques to boost traffic to their landing pages.
Spoofed software portals appearing in search engine results
For example, here is how the fraudulent download portal for DNS Jumper looks:
Fake website mimicking the official DNS Jumper resource
On this page, the download button directs users to the following address:
Just like the OBS Studio variant, this drops an archive onto the victim’s device with an identical structure: a renamed legitimate install.exe file, a sideloaded library, and an Assets directory containing the promised software packaged alongside ScreenConnect.
Contents of the DNS Jumper and ScreenConnect archive
Other fraudulent websites that appear in search engine results when querying the corresponding software are designed in a similar fashion.
Spoofed websites used to distribute ScreenConnect
Notably, the vast majority of the fraudulent sites we uncovered are localized into English, Russian, and Chinese. In several instances, the pages were also translated into German, French, Spanish, Arabic, and other languages. This multi-language support underscores the global footprint of the campaign, targeting a broad user base across multiple regions.
Language localization options on a ScreenConnect delivery site
To distribute ScreenConnect disguised as freeware, the threat actor spun up an extensive network of domain names mapped across three IP addresses. We have categorized these into two distinct infrastructure clusters.
The connection graph below illustrates the campaign websites tied to IP address 162.216.241[.]242 , which hosts the previously mentioned www[.]studioobs[.]com domain.
URL connection graph for IP 162.216.241[.]242 Looking into the registration dates for the domains on this IP, we found that the threat actor initially attempted to disguise their sites as various gaming portals:
URL connection graph for IP 162.216.241[.]242
Subsequently, starting in January 2026, they shifted strategy and began registering fake domains designed to mimic popular freeware:
In this specific branch of the ScreenConnect campaign, the malicious archives are hosted on fileget.loseyourip[.]com . Notably, the download resource is hosted on a completely separate provider:
Our analysis of this second IP address revealed that it also hosts additional resources tied to the campaign, including fake gaming sites and supplementary download links:
URL connection graph for IP 198.23.185[.]81
Below is an infrastructure graph showing this IP address and its hosted domains. Notably, unlike the previous case, this address also hosts direct-download.giize[.]com , a resource used to store distributed malicious archives.
URL connection graph for IP 2.59.134[.]97 In this branch of the campaign, the threat actor skipped game-themed lures entirely, focusing exclusively on creating fraudulent freeware sites that bundled ScreenConnect with the requested application. The domains hosted on IP address 2.59.134[.]97 were registered between October 2025 and March 2026.
URL connection graph for IP 2.59.134[.]97
The chart below shows the volume of fraudulent websites created month by month:
Breakdown of ScreenConnect delivery sites by theme, August 2025 through March 2026 ( download )
In total, we identified dozens of different archives distributed across this campaign. All of them share a uniform file structure, containing the malicious install.res.1033.dll library and the ScreenConnect MSI package located at Assets\x86\vcredist_x64.dll .
In some instances, the ScreenConnect installation package also bundles a CAB archive.
Contents of the CAB archive
This archive contains a system.config XML file, which defines the connection address for the ScreenConnect C2 server:
Contents of system.config
By analyzing these ScreenConnect installations, we uncovered additional C2 addresses, which are mapped out in the following graph:
Connection graph of ScreenConnect C2 domains
The next graph illustrates the AsyncRAT command-and-control infrastructure:
AsyncRAT C2 server infrastructure
Based on the registration dates of the C2 domains, we can determine that the campaign was launched in October 2025 and paused at the end of March. However, at the time of publication, many of the landing pages remain accessible via search engine results.
Investigating a single case of AsyncRAT delivered via ScreenConnect allowed us to uncover a massive, multi-domain, multi-language infrastructure designed to distribute a hidden installer for this software and further advance the attack. The threat actor disguises ScreenConnect as popular utilities and distributes it through fraudulent websites that mimic official product pages. The attackers leverage search engine optimization techniques to push these sites to the top of search results in engines like Google and Bing.
This attack chain targets both everyday consumers downloading free software from the internet and corporate networks, where remote access tools are frequently allowlisted and granted elevated privileges.
The potential objective of the campaign is to steal credentials en masse and gain unauthorized access to systems for subsequent resale on dark web marketplaces.
To mitigate the risks associated with this threat, we recommend implementing the following security measures:
Enforce strict software installation controls: application allowlisting and blocking MSI package execution from untrusted sources
Continuously monitor for the creation of new remote administration services and scheduler tasks
Filter outbound traffic to unknown domains and IP addresses
Regularly train users on safe downloading practices
Verify the authenticity of all software sources
For enterprise users, credential monitoring is a critical mitigation strategy against the risks detailed in this article, as a leaked account or compromised system access frequently serves as a vector for subsequent attacks on the organization. Kaspersky Digital Footprint Intelligence provides continuous data monitoring across open and dark web sources, enabling security teams to respond proactively to potential threats.
Kaspersky Managed Detection and Response detects the malicious activity described in this post using the following indicators of attack:
ScreenConnect service creation with suspicious parameters logsource: product: windows category: security detection: selection_access: EventID: 4697 Service File Name|contains: - 'e=Access' - 'ClientService.exe' selection_support: EventID: 4697 Service File Name|contains: - 'e=Support' - 'ClientService.exe' condition: selection_access or selection_support 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 logsource : product : windows category : security detection : selection_access : EventID : 4697 Service File Name | contains : - 'e=Access' - 'ClientService.exe' selection_support : EventID : 4697 Service File Name | contains : - 'e=Support' - 'ClientService.exe' condition : selection_access or selection_support
Anomalous child processes being spawned by the ScreenConnect service logsource: product: windows category: process_creation detection: selection: ParentImage|endswith: - '\\ScreenConnect.ClientService.exe' - '\\ScreenConnect.WindowsClient.exe' - '\\ScreenConnect.WindowsBackstageShell.exe' - '\\ScreenConnect.WindowsFileManager.exe' Image|endswith: - '\\powershell.exe' - '\\cmd.exe' - '\\net.exe' - '\\schtasks.exe' - '\\sc.exe' - '\\msiexec.exe' - '\\mshta.exe' - '\\rundll32.exe' condition: selection 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 logsource : product : windows category : process_creation detection : selection : ParentImage | endswith : - '\\ScreenConnect.ClientService.exe' - '\\ScreenConnect.WindowsClient.exe' - '\\ScreenConnect.WindowsBackstageShell.exe' - '\\ScreenConnect.WindowsFileManager.exe' Image | endswith : - '\\powershell.exe' - '\\cmd.exe' - '\\net.exe' - '\\schtasks.exe' - '\\sc.exe' - '\\msiexec.exe' - '\\mshta.exe' - '\\rundll32.exe' condition : selection
Additionally, Kaspersky products detect the malware covered in this post under the following verdicts:
Trojan.Win64.DLLhijack.*
Trojan.PowerShell.Agent.bav
Endpoint malicious activity can be monitored using Kaspersky EDR Expert . Specifically, security teams should look for the execution of commands and scripts containing suspicious patterns, such as XOR operations used for command and data obfuscation by malware operating on the host. This activity is flagged by the suspicious_assembly_loading_into_powershell_via_reflection_amsi and xored_powershell_command_amsi rules.
Additionally, persistence mechanisms involving the creation, modification, or utilization of scheduled tasks via the schtasks.exe utility are caught by the scheduled_task_create_from_public_directory_via_schtasks rule.
Malicious code injection into the RegAsm.exe process — leveraged by attackers to masquerade execution behind a trusted system component — is detected via the code_injection_to_unusual_process rule.
To visualize the stages of the attack, security teams can utilize Kaspersky Cloud Sandbox on the Threat Intelligence portal. For instance, this tool allows defenders to map out the entire deployment and payload execution chain originating from the initial VBS dropper.
Furthermore, the Kaspersky Threat Intelligence portal supports searching and graphing the connections between malicious domains and files involved in this campaign, as demonstrated in our adversary infrastructure analysis section .
Finally, the Similarity engine within Kaspersky Threat Analysis profiles file contents to hunt down samples resembling the original threat, helping organizations identify new or previously undetected malicious objects.
To protect companies using our Kaspersky SIEM system , there are rules available in the product repository to help detect this type of malicious activity.
Adding exclusions to Windows Defender scans via the registry is detected by rule R241_Modification of Windows Defender exclusions through the registry . Adding exclusions via PowerShell ( Add-MpPreference -ExclusionPath|ExclusionProcess ) is detected by rule R076_04_Windows Defender settings disabled or changed via PowerShell .
Bypassing the UAC mechanism by modifying the ConsentPromptBehaviorAdmin registry key is detected by rule R242_UAC disabled through the Windows registry .
Running VBS scripts from a public directory triggers rule R290_07_Running VBScript files from shared folders .
Creating a scheduled task that runs an executable file from a public directory triggers rule R099_01_Scheduled task started from a public folder .
For the rules to function correctly, it is necessary to configure event 4657 (Security) audit for the following registry keys:
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Procesess
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
Additionally, when developing your own detection rules or conducting threat hunting for suspicious ScreenConnect behavior, we recommend monitoring the following events:
Creation of the ScreenConnect service with suspicious parameters DeviceEventClassID = '4697' AND FileName LIKE '%ClientService.exe%' AND (FileName LIKE '%e=Access%' OR FileName LIKE '%e=Support%') 1 2 3 DeviceEventClassID = '4697' AND FileName LIKE '%ClientService.exe%' AND ( FileName LIKE '%e=Access%' OR FileName LIKE '%e=Support%' )
Launch of atypical child processes from the ScreenConnect service DeviceEventClassID = '4688' AND match(SourceProcessName, '.*\\\\ScreenConnect\\.(ClientService|WindowsClient|WindowsBackstageShell|WindowsFileManager)\\.exe') AND match(DestinationProcessName, '.*\\\\(powershell|cmd|net|schtasks|sc|msiexec|mshta|rundll32)\\.exe') 1 2 3 DeviceEventClassID = '4688' AND match ( SourceProcessName , '.*\\\\ScreenConnect\\.(ClientService|WindowsClient|WindowsBackstageShell|WindowsFileManager)\\.exe' ) AND match ( DestinationProcessName , '.*\\\ \ ( powershell | cmd | net | schtasks | sc | msiexec | mshta | rundll32 ) \\.exe' )
B32810973132D11AFD61CCEE222BBB79 5B7E1FE55BD7B5EA54BD4ED1677E5A26 9A9CCD8B0E5D05F4EE77667B024844DB 0EEE9BAD07E22415439E854657FA1366 8F4E8B680D3E8D3F5AC39BD72882F713
5F96C04E3AFAE97017B201BE112284D2 73BEAD922109A61E5F9F85771A7812C5 EDFF4F58722C93D7C09ED71899416396 83601C3D4ED28E8D2BE1B99BEB8EC18C 695E794631EF130583368770E7B81E98 83601C3D4ED28E8D2BE1B99BEB8EC18C 1E6A5C7B620D487D0CFC6874C3B77C90 54025CE2A9405039899FE99A1D77E0BB BD05FCF80E493CF9AA71EC510319469D 999A63730C9634481D1D76955A2E76A8 479BD3BB617B39CD4A46D0768A2592D4 776DFD3DF9C04BB9FCDD6C1880C3761A 8E4C57358A66EB14D31ABB614DDC68DE A40D3AEB0DAE5B00BDB3A517F3135BBB A85A5BFDCB7C65AB93043B8CF9E20065 01325880EFFFEC546F59490089A3B415
mora1987[.]work[.]gd
ds4windows[.]io direct-download[.]giize[.]com tmodloader[.]org tmodloader[.]app ds4windows[.]net losslessscaling[.]app processhacker[.]dev steamtools[.]pro dnsjumper[.]app free-download[.]camdvr[.]org defendercontrol[.]org dns-jumper[.]com cpuz[.]app processhacker[.]org processhacker[.]app steamtools[.]cc cpuz[.]pro wallpaper-engine[.]app processhacker[.]net antimicrox[.]net defendercontrol[.]app tmodloader[.]pro dnsjumper[.]io bandicam[.]app mgba[.]app dnsjumper[.]pro ferdium[.]app ds4windows[.]pro lossless-scaling[.]online defender-control[.]com gom-player[.]app defendercontrol[.]pro lossless-scaling[.]download antimicrox[.]pro mgba[.]pro lossless-scaling[.]app losslessscaling[.]pro mgba[.]dev tmodloader[.]download tmod-loader[.]com defendercontrol[.]download ferdium[.]pro deadreset[.]com gom-player[.]net crosshairx[.]pro libreoffice[.]pro studioobs[.]com studio-obs[.]net crosshairxv2[.]com km-player[.]com corel-draw[.]net glary-utilities[.]com download-full-version[.]ooguy[.]com crosshair-x[.]com kms-tools[.]com studio-obs[.]com crosshairx[.]net clair-obscur-33[.]com vlc-player[.]net arksurvival-ascended[.]com elden-ringnightreign[.]com ready-ornot[.]com arma-reforger[.]com crusader-kings[.]com crosshairx2[.]com mediaplayerclassic[.]net bandizip[.]pro obs-studio[.]site ovr-advanced-settings[.]com studio-obs[.]pro vlc-media[.]com clair-obscur-33[.]town ovr-toolkit[.]com crusader-kings[.]church bandizip[.]net apexlegends[.]org obs-studio[.]pro vlc-media[.]net crosshairx[.]site monster-hunterwilds[.]com km-player[.]pro mediaplayerclassic[.]pro kms-tools[.]net fernbus-simulator[.]com studioobs[.]pro bandicam[.]cc crystaldiskmark[.]cc crystaldiskmark[.]io crystaldiskmark[.]dev crystaldiskmark[.]app crystaldiskmark[.]pro bandicam[.]io
fileget.loseyourip[.]com file-download-crosshairx.giize[.]com all-toll-free.loseyourip[.]com mpc-update.giize[.]com all-toll-free.publicvm[.]com 198.23.185[.]81 direct-download.giize[.]com
servermanagemen[.]xyz 185.254.97[.]249 r.manage-server[.]xyz 45.145.41[.]205 winservec[.]net manageserver[.]xyz cloudsynn[.]com pingserv[.]pro ehostservers[.]xyz serverdnsplan[.]net pingpanl[.]pro managedevice[.]xyz edgeserv[.]ru
Malware Technologies
Kaspersky Security Services
The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
This site uses Akismet to reduce spam. Learn how your comment data is processed.
更新于 2026 年 7 月 3 日
初步事件调查
ScreenConnect是如何进入系统的
扩大调查范围
虚假域名基础设施
集群 1:162.216.241[.]242 和 198.23.185[.]81
集群 2:2.59.134[.]97
C2基础设施分析
卡巴斯基解决方案的检测
妥协的迹象
恶意库:install.res.1033.dll
虚假网站地址
更新 03.07.2026:添加了一系列规则和建议,以帮助使用我们卡巴斯基 SIEM 系统的公司检测所描述的恶意活动。
为了访问被入侵的系统,攻击者经常滥用合法的远程监控工具。乍一看,这些工具似乎并不可疑:它们使用有效的数字证书签名,通常被列入企业 IT 策略的白名单,并得到操作系统厂商的全面支持。然而,它们却赋予攻击者从目标设备窃取数据、植入恶意软件以及在网络中横向移动的能力。
在最近的一次调查中,卡巴斯基托管检测与响应 (MDR) 团队发现有人利用 ScreenConnect 远程访问工具部署和执行 AsyncRAT 有效载荷。
对这起事件的深入调查揭露了一场大规模的恶意活动,该活动通过伪造的网站分发恶意安装程序。这些安装程序伪装成 OBS Studio、DNS Jumper、DS4Windows、Bandicam 等热门软件。我们总共发现了超过 90 个域名,涵盖 10 种语言。这些恶意程序包中包含一个合法的、经过签名的 Microsoft install.exe 二进制文件,以及一个恶意 install.res.1033.dll 库。它通过 DLL 侧加载加载到设备上,并部署 ScreenConnect 服务,该服务等待攻击者的进一步指令。
因此,最初看似孤立的ScreenConnect事件,却成为了对攻击者C2基础设施进行全面调查的起点。我们发现的每一个仿冒网站都遵循着完全相同的策略:伪装成合法的软件安装程序,投放隐藏的ScreenConnect远程管理服务。这使得攻击者能够控制被入侵的终端,受害者涵盖个人用户到组织机构。
在持续更新的“安全运营中心档案”系列文章中,我们将继续剖析此类复杂的多阶段安全事件。在本文中,我们将深入分析ScreenConnect攻击的技术执行过程,并分析攻击者控制的更广泛的基础设施。
此次调查是由卡巴斯基 MDR 发出的警报引发的,该警报标记了由 ScreenConnect 进程生成的可疑 PowerShell 和 VBS 脚本的创建和执行。
ScreenConnect 是一个合法的远程管理实用程序。卡巴斯基解决方案将其检测为非病毒:HEUR:RemoteAdmin.MSIL.ConnectWise.gen。
ScreenConnect 作为 Access 类型的服务运行,支持直接远程连接,服务器地址通过命令行显式传递:
ScreenConnect 服务执行事件,包含可疑参数
ScreenConnect 运行后,创建并执行了一个名为 Fj5NmEsp9EuKrun.ps1 的 PowerShell 脚本:
创建恶意 PowerShell 脚本
以下是剧本内容的节选:
Fj5NmEsp9EuKrun.ps1 片段
此脚本配置 Microsoft Defender 对以下对象的排除项:
系统中的所有磁盘:C:\、D:\ 及其他磁盘
C:\ 驱动器上的所有根目录,以及 C:\Users\Public 目录
此外,该脚本通过将 ConsentPromptBehaviorAdmin 注册表参数设置为 0 来禁用用户帐户控制 (UAC) 提示。
完成上述设置后,ScreenConnect 服务将继续创建一个 VBScript 文件:
恶意 VBScript 创建
installer_method3_stream.vbs 脚本在 C:\Users\Public 目录中创建五个文件(msgbox.txt、secret_bytes.txt、1.vb、cap.ps1 和 script.vbs),并通过启动 script.vbs 立即触发它们的执行。
script.vbs 的内容
该脚本会终止所有活动的 powershell.exe 进程以掩盖其踪迹,并在隐藏窗口中执行 cap.ps1。
cap.ps1 读取 secret_bytes.txt 文件的内容,提取符合 [SXX- 模式的序列,并将 XX 从十六进制表示转换为字节。然后,它使用 0xA7 异或密钥解密每个字节并反转位顺序。生成的字节数组构成一个完整的 PE 二进制文件,然后通过反射加载到 CLR 中。
在已加载的程序集中,ConsoleApp1.Module1 类型包含一个名为 Run 的静态方法。该脚本使用反射(Reflection.BindingFlags)来解析对此方法的引用并调用它。
Run 方法执行进程空洞化技术 (T1055.012),生成一个带有 CREATE_SUSPENDED 标志的新 RegAsm.exe 进程。然后,从 secret_bytes.txt 中反混淆和解密的 PE 镜像被复制到该进程的地址空间。因此,RegAsm.exe 进程不再执行其原始代码,而是作为注入的 .NET 模块(在本例中为 AsyncRAT 远程访问木马)的容器。
为了建立持久性,该恶意软件会安排一个名为 MasterPackager.Updater 的任务:
该任务每两分钟触发一次,确保 script.vbs(以及整个加载器链)即使在系统重启后也能执行。
一旦整个感染链成功执行,RegAsm.exe 进程就会与 C2 域 mora1987[.]work[.]gd 建立连接。
AsyncRAT 通过 ScreenConnect 进行感染和持久化。
对该事件的回顾性分析使我们能够确定 ScreenConnect 安装的来源:一个名为 obs-studio-windows-x64.zip 的用户下载的存档。
该压缩文件是从 hxxps://www.studioobs[.]com/ 下载的,这是一个域名抢注网站,模仿了流行的开源屏幕录制应用 OBS Studio 的官方网站。该网站出现在搜索引擎结果中;在本例中,用户直接通过搜索查询访问了该恶意域名,我们将在下文详细分析这一攻击途径。
点击看似合法的软件下载按钮,会触发对以下 URL 的请求,并从中获取压缩文件:
用于提供 ScreenConnect 服务的网站
该压缩包包含一个名为 install.exe (87603EA025623B19954E460ADD532048) 的合法、经微软签名的可执行文件,该文件被重命名以伪装成 OBS Studio 安装程序,同时还包含一个名为 install.res.1033.dll 的恶意库。此外,该压缩包还包含一个 Assets 文件夹,其中包含被冒充的实际软件副本和 ScreenConnect 实用程序。
obs-studio-windows-x64.zip 的内容
该归档文件的完整文件结构如下:
obs-studio-windows-x64.zip 的详细目录树
当执行 OBS-Studio-Installer.exe 时,它会通过 DLL 侧加载加载 install.res.1033.dll。该库包含安装 ScreenConnect 和 OBS Studio 所需的指令。部署过程依赖于 Windows 原生实用程序 (msiexec.exe),但攻击者已将标准的 MSI 包重命名,使其看起来像 DLL 文件:
Assets\x86\Data\vcredist_x64.dll:ScreenConnect 安装程序
Assets\x86\Data\vcredist_x86.dll:OBS Studio 安装程序
vcredist_x64.dll MSI 包的内容如下所示:
ScreenConnect 安装文件
Windows Installer 程序会在后台静默安装 ScreenConnect,无需重启系统:
安装完成后,将创建一个名为 Microsoft Update Service 的新服务。该服务的命令行明确地将连接服务器定义为 r[.]servermanagemen[.]xyz。
同时,实际的 OBS Studio 软件的 MSI 软件包使用标准图形用户界面运行。
ScreenConnect 和 OBS Studio 安装工作流程
攻击者对合法 install.exe 二进制文件的依赖,为我们更广泛的调查提供了关键的切入点。我们发现,这个特定的文件在实际环境中以各种可疑的别名进行部署,包括:
crosshairx_installer.exe
obs-studio-installer.exe
glary utilities pro.exe
processhacker-2.39-setup.exe
这些文件名表明,攻击者将 ScreenConnect 压缩包伪装成 OBS Studio 以外的常用工具。在这些伪造文件中,我们发现了 DS4Windows、DNS Jumper、Glary Utilities 和 Process Hacker 的伪造安装程序。关键在于,当我们在主流搜索引擎上搜索这些工具时,这些欺诈网站经常出现在自然搜索结果的顶部。这表明攻击者正在积极利用搜索引擎优化 (SEO) 技术来提升其目标页面的流量。
搜索引擎结果中出现的欺骗性软件门户网站
例如,下图是 DNS Jumper 的欺诈性下载门户网站:
模仿官方 DNS Jumper 资源的虚假网站
本页面上的下载按钮会将用户引导至以下地址:
与 OBS Studio 变种一样,此程序会在受害者的设备上放置一个结构相同的存档:一个重命名的合法 install.exe 文件、一个侧载库以及一个 Assets 目录,其中包含承诺的与 ScreenConnect 一起打包的软件。
DNS Jumper 和 ScreenConnect 存档的内容
在搜索引擎中搜索相应软件时出现的其他欺诈网站也采用类似的设计方式。
用于分发 ScreenConnect 的仿冒网站
值得注意的是,我们发现的绝大多数欺诈网站都提供英语、俄语和中文版本。在一些案例中,页面还被翻译成德语、法语、西班牙语、阿拉伯语和其他语言。这种多语言支持凸显了此次活动的全球性,其目标用户群体遍布多个地区。
ScreenConnect交付网站上的语言本地化选项
为了将 ScreenConnect 伪装成免费软件进行分发,攻击者搭建了一个庞大的域名网络,这些域名映射到三个 IP 地址上。我们已将这些域名网络归类为两个不同的基础设施集群。
下面的连接图显示了与 IP 地址 162.216.241[.]242 关联的活动网站,该 IP 地址托管了前面提到的 www[.]studioobs[.]com 域名。
IP 地址 162.216.241[.]242 的 URL 连接图。通过查看该 IP 地址下域名的注册日期,我们发现攻击者最初试图将其网站伪装成各种游戏门户网站:
IP 地址 162.216.241[.]242 的 URL 连接图
随后,从 2026 年 1 月开始,他们改变了策略,开始注册旨在模仿流行免费软件的虚假域名:
在 ScreenConnect 攻击活动的这一特定分支中,恶意压缩文件托管在 fileget.loseyourip[.]com 上。值得注意的是,下载资源托管在一个完全不同的提供商处:
我们对第二个 IP 地址的分析显示,它还托管着与该活动相关的其他资源,包括虚假游戏网站和补充下载链接:
IP 地址 198.23.185[.]81 的 URL 连接图
下图展示了该 IP 地址及其托管的域名。值得注意的是,与之前的案例不同,该地址还托管了 direct-download.giize[.]com,这是一个用于存储分布式恶意文件的资源。
IP地址2.59.134[.]97的URL连接图。在此攻击活动中,攻击者完全跳过了游戏主题的诱饵,而是专注于创建欺诈性的免费软件网站,将ScreenConnect与请求的应用程序捆绑在一起。IP地址2.59.134[.]97上托管的域名注册于2025年10月至2026年3月之间。
IP地址2.59.134[.]97的URL连接图
下图显示了每月创建的欺诈网站数量:
ScreenConnect 内容分发站点按主题细分,2025 年 8 月至 2026 年 3 月(下载)
我们总共发现了数十个分布在此次攻击活动中的不同归档文件。所有这些归档文件都具有统一的文件结构,包含恶意 install.res.1033.dll 库和位于 Assets\x86\vcredist_x64.dll 的 ScreenConnect MSI 包。
在某些情况下,ScreenConnect 安装包还会捆绑一个 CAB 存档。
CAB档案的内容
此压缩包包含一个 system.config XML 文件,其中定义了 ScreenConnect C2 服务器的连接地址:
system.config 的内容
通过分析这些 ScreenConnect 安装,我们发现了额外的 C2 地址,如下图所示:
ScreenConnect C2 域的连接图
下图展示了 AsyncRAT 的命令与控制基础架构:
AsyncRAT C2 服务器基础架构
根据C2域名的注册日期,我们可以确定该推广活动于2025年10月启动,并于3月底暂停。然而,截至发稿时,许多落地页仍然可以通过搜索引擎结果访问。
通过调查一起利用 ScreenConnect 传播的 AsyncRAT 案例,我们发现了一个庞大的、跨域名、跨语言的攻击基础设施,该基础设施旨在分发此软件的隐藏安装程序并进一步推进攻击。攻击者将 ScreenConnect 伪装成常用实用程序,并通过模仿官方产品页面的欺诈网站进行分发。他们利用搜索引擎优化技术,将这些网站推至 Google 和 Bing 等搜索引擎结果的顶部。
这种攻击链的目标既包括从互联网下载免费软件的普通消费者,也包括企业网络,在这些网络中,远程访问工具经常被列入白名单并被授予更高的权限。
该行动的潜在目标是大规模窃取凭证,未经授权访问系统,然后在暗网市场上转售。
为降低此威胁带来的风险,我们建议实施以下安全措施:
实施严格的软件安装控制:应用程序白名单机制,并阻止从不受信任的来源执行 MSI 程序包。
持续监控新创建的远程管理服务和调度任务
过滤发往未知域名和 IP 地址的出站流量
定期对用户进行安全下载操作培训。
验证所有软件来源的真实性
对于企业用户而言,凭证监控是应对本文详述风险的关键缓解策略,因为账户泄露或系统访问权限被盗用往往会成为后续攻击组织的途径。卡巴斯基数字足迹情报提供对开放网络和暗网资源的持续数据监控,使安全团队能够主动应对潜在威胁。
卡巴斯基托管检测与响应 (Kaspersky Managed Detection and Response) 使用以下攻击指标检测本文所述的恶意活动:
使用可疑参数创建 ScreenConnect 服务日志源:产品:Windows 类别:安全 检测:选择访问:事件 ID:4697 服务文件名 | 包含:- 'e=Access' - 'ClientService.exe' 选择支持:事件 ID:4697 服务文件名 | 包含:- 'e=Support' - 'ClientService.exe' 条件:选择访问或选择支持 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 日志源:产品:Windows 类别:安全 检测:选择访问:事件 ID:4697 服务文件名 | 包含:- 'e=Access' - 'ClientService.exe' 选择支持:事件 ID:4697 服务文件名 | 包含:- 'e=Support' - 'ClientService.exe' 条件:选择访问或选择支持
ScreenConnect 服务日志源中检测到异常子进程:产品:Windows 类别:进程创建 检测:选择:父映像|以以下结尾:- '\\ScreenConnect.ClientService.exe' - '\\ScreenConnect.WindowsClient.exe' - '\\ScreenConnect.WindowsBackstageShell.exe' - '\\ScreenConnect.WindowsFileManager.exe' 映像|以以下结尾:- '\\powershell.exe' - '\\cmd.exe' - '\\net.exe' - '\\schtasks.exe' - '\\sc.exe' - '\\msiexec.exe' - '\\mshta.exe' - '\\rundll32.exe' 条件:选择 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 logsource : product : windows category : process_creation detection : selection : ParentImage | endswith : - '\\ScreenConnect.ClientService.exe' - '\\ScreenConnect.WindowsClient.exe' - '\\ScreenConnect.WindowsBackstageShell.exe' - '\\ScreenConnect.WindowsFileManager.exe' Image | endswith : - '\\powershell.exe' - '\\cmd.exe' - '\\net.exe' - '\\schtasks.exe' - '\\sc.exe' - '\\msiexec.exe' - '\\mshta.exe' - '\\rundll32.exe' condition : selection
此外,卡巴斯基产品对本文中提到的恶意软件的检测结果如下:
Trojan.Win64.DLL劫持.*
Trojan.PowerShell.Agent.bav
可以使用 Kaspersky EDR Expert 监控端点恶意活动。具体来说,安全团队应查找包含可疑模式的命令和脚本的执行情况,例如恶意软件在主机上运行时用于混淆命令和数据的 XOR 操作。此类活动会被 `suspicious_assembly_loading_into_powershell_via_reflection_amsi` 和 `xored_powershell_command_amsi` 规则标记。
此外,通过 schtasks.exe 实用程序创建、修改或使用计划任务的持久性机制会被 schedule_task_create_from_public_directory_via_schtasks 规则捕获。
通过 code_injection_to_unusual_process 规则可以检测到向 RegAsm.exe 进程注入恶意代码(攻击者利用此漏洞伪装成在受信任的系统组件后面执行)。
为了可视化攻击的各个阶段,安全团队可以利用威胁情报门户上的卡巴斯基云沙箱。例如,该工具允许防御者绘制出从初始 VBS 投放器开始的整个部署和有效载荷执行链。
此外,卡巴斯基威胁情报门户支持搜索和绘制此次攻击活动中涉及的恶意域和文件之间的联系,正如我们在对手基础设施分析部分中所展示的那样。
最后,卡巴斯基威胁分析中的相似性引擎会对文件内容进行分析,以查找与原始威胁相似的样本,帮助组织识别新的或以前未检测到的恶意对象。
为了保护使用我们卡巴斯基 SIEM 系统的公司,产品库中提供了一些规则,可以帮助检测此类恶意活动。
通过注册表向 Windows Defender 扫描添加排除项的操作会被规则 R241_通过注册表修改 Windows Defender 排除项检测到。通过 PowerShell(Add-MpPreference -ExclusionPath|ExclusionProcess)添加排除项的操作会被规则 R076_04_通过 PowerShell 禁用或更改 Windows Defender 设置检测到。
通过修改 ConsentPromptBehaviorAdmin 注册表项绕过 UAC 机制的行为会被规则 R242_UAC 检测到,该规则已通过 Windows 注册表禁用。
从公共目录运行 VBS 脚本会触发规则 R290_07_从共享文件夹运行 VBScript 文件。
创建从公共目录运行可执行文件的计划任务会触发规则 R099_01_从公共文件夹启动的计划任务。
为了使规则正常运行,需要为以下注册表项配置事件 4657(安全)审核:
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processess
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
此外,在制定您自己的检测规则或进行针对可疑 ScreenConnect 行为的威胁搜寻时,我们建议监控以下事件:
创建 ScreenConnect 服务时使用了可疑参数 DeviceEventClassID = '4697' AND FileName LIKE '%ClientService.exe%' AND (FileName LIKE '%e=Access%' OR FileName LIKE '%e=Support%') 1 2 3 DeviceEventClassID = '4697' AND FileName LIKE '%ClientService.exe%' AND ( FileName LIKE '%e=Access%' OR FileName LIKE '%e=Support%' )
从 ScreenConnect 服务启动非典型子进程 DeviceEventClassID = '4688' AND match(SourceProcessName, '.*\\\\ScreenConnect\\.(ClientService|WindowsClient|WindowsBackstageShell|WindowsFileManager)\\.exe') AND match(DestinationProcessName, '.*\\\\(powershell|cmd|net|schtasks|sc|msiexec|mshta|rundll32)\\.exe') 1 2 3 DeviceEventClassID = '4688' AND match ( SourceProcessName , '.*\\\\ScreenConnect\\.(ClientService|WindowsClient|WindowsBackstageShell|WindowsFileManager)\\.exe' ) AND match ( DestinationProcessName , '.*\\\ \ ( powershell | cmd | net | schtasks | sc | msiexec | mshta | rundll32 ) \\.exe' )
B32810973132D11AFD61CCEE222BBB79 5B7E1FE55BD7B5EA54BD4ED1677E5A26 9A9CCD8B0E5D05F4EE77667B024844DB 0EEE9BAD07E22415439E854657FA1366 8F4E8B680D3E8D3F5AC39BD72882F713
5F96C04E3AFAE97017B201BE112284D2 73BEAD922109A61E5F9F85771A7812C5 EDFF4F58722C93D7C09ED71899416396 83601C3D4ED28E8D2BE1B99BEB8EC18C 695E794631EF130583368770E7B81E98 83601C3D4ED28E8D2BE1B99BEB8EC18C 1E6A5C7B620D487D0CFC6874C3B77C90 54025CE2A9405039899FE99A1D77E0BB BD05FCF80E493CF9AA71EC510319469D 999A63730C9634481D1D76955A2E76A8 479BD3BB617B39CD4A46D0768A2592D4 776DFD3DF9C04BB9FCDD6C1880C3761A 8E4C57358A66EB14D31ABB614DDC68DE A40D3AEB0DAE5B00BDB3A517F3135BBB A85A5BFDCB7C65AB93043B8CF9E20065 01325880EFFFEC546F59490089A3B415
mora1987[.]work[.]gd
ds4windows[.]io direct-download[.]giize[.]com tmodloader[.]org tmodloader[.]app ds4windows[.]net losslessscaling[.]app processhacker[.]dev steamtools[.]pro dnsjumper[.]app free-download[.]camdvr[.]org defendercontrol[.]org dns-jumper[.]com cpuz[.]app processhacker[.]org processhacker[.]app steamtools[.]cc cpuz[.]pro wallpaper-engine[.]app processhacker[.]net antimicrox[.]net defendercontrol[.]app tmodloader[.]pro dnsjumper[.]io bandicam[.]app mgba[.]app dnsjumper[.]pro ferdium[.]app ds4windows[.]pro lossless-scaling[.]online defender-control[.]com gom-player[.]app defendercontrol[.]pro lossless-scaling[.]download antimicrox[.]pro mgba[.]pro lossless-scaling[.]app losslessscaling[.]pro mgba[.]dev tmodloader[.]download tmod-loader[.]com defendercontrol[.]download ferdium[.]pro deadreset[.]com gom-player[.]net crosshairx[.]pro libreoffice[.]pro studioobs[.]com studio-obs[.]net crosshairxv2[.]com km-player[.]com corel-draw[.]net glary-utilities[.]com download-full-version[.]ooguy[.]com crosshair-x[.]com kms-tools[.]com studio-obs[.]com crosshairx[.]net clair-obscur-33[.]com vlc-player[.]net arksurvival-ascended[.]com elden-ringnightreign[.]com ready-ornot[.]com arma-reforger[.]com crusader-kings[.]com crosshairx2[.]com mediaplayerclassic[.]net bandizip[.]pro obs-studio[.]site ovr-advanced-settings[.]com studio-obs[.]pro vlc-media[.]com clair-obscur-33[.]town ovr-toolkit[.]com crusader-kings[.]church bandizip[.]net apexlegends[.]org obs-studio[.]pro vlc-media[.]net crosshairx[.]site monster-hunterwilds[.]com km-player[.]pro mediaplayerclassic[.]pro kms-tools[.]net fernbus-simulator[.]com studioobs[.]pro bandicam[.]cc crystaldiskmark[.]cc crystaldiskmark[.]io crystaldiskmark[.]dev crystaldiskmark[.]app crystaldiskmark[.]pro bandicam[.]io
fileget.loseyourip[.]com file-download-crosshairx.giize[.]com all-toll-free.loseyourip[.]com mpc-update.giize[.]com all-toll-free.publicvm[.]com 198.23.185[.]81 direct-download.giize[.]com
servermanagemen[.]xyz 185.254.97[.]249 r.manage-server[.]xyz 45.145.41[.]205 winservec[.]net manageserver[.]xyz cloudsynn[.]com pingserv[.]pro ehostservers[.]xyz serverdnsplan[.]net pingpanl[.]pro managedevice[.]xyz edgeserv[.]ru
恶意软件技术
卡巴斯基安全服务
SOC档案:伪装成免费软件的ScreenConnect。深入剖析一场大规模的攻击活动。
本网站使用 Akismet 来减少垃圾邮件。了解您的评论数据如何处理。