Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Asyncrat exploits ConnectWise ScreenConnect to steal credentials and ciphers
Celebrities

Asyncrat exploits ConnectWise ScreenConnect to steal credentials and ciphers

By September 11, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 11, 2025Ravi LakshmananMalware/Certifications

Cybersecurity researchers reveal details of a new campaign that leverages ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) software, delivering a meatless loader that drops a remote access Trojan (RAT), called Asyncrat, to steal sensitive data from a reduced-down host.

“The attacker used ScreenConnect to gain remote access and ran a layered VBScript and PowerShell loader that retrieves and runs obfuscated components from external URLs,” LevelBlue said in a report shared with Hacker News. “These components are encoded .NET assemblies that are eventually deactivated to Asyncrat, while maintaining persistence via fake ‘Skype Updater’ scheduled tasks. ”

The infection chain documented by cybersecurity companies has shown that threat actors leverage the deployment of Screen Connect to launch remote sessions and start visual basic script payloads via keyboard activity.

“We’ve seen a Trojan screenconnect installer disguised as financial and other business documents sent via phishing emails,” Leadblue MDR SOC analyst Sean Shirley told Hacker News.

Audit and subsequent

The script is designed to use PowerShell scripts to retrieve two external payloads (“logs.ldk” and “logs.ldr”) from the attacker control server. The first of the two files is a DLL that is used to establish persistence using scheduled tasks by writing a secondary visual basic script on disk and by avoiding detection as “Skype Updater” and establishing saves using disks.

This visual basic script contains the same PowerShell logic observed at the start of the attack. Scheduled tasks ensure that the payload will run automatically every time you log in.

In addition to loading “logs.ldk” as a .NET assembly, the PowerShell script is passed as input to the load assembly, leading to the execution of the binary (“asyncclient.exe”). Browser extensions for Google Chrome, Brave, Microsoft Edge, Opera, and Mozilla Firefox.

All this collected information will eventually be extended to the Command and Control (C2) server (“3osch20.duckdns”[.]org”) via TCP socket, a malware beacon uses a beacon to perform a payload and receive commands after explosion. C2 connection settings are hardcoded or extracted from the remote path pebin URL.

“Fireless malware continues to pose major challenges to modern cybersecurity defenses due to its stealthiness and reliance on legitimate system tools for execution,” LevelBlue said. “Unlike traditional malware that writes payloads to disk, indelible threats work in memory, making them difficult to detect, analyze and eradicate.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCalifornia bill regulating AI companion chatbots is approaching the law
Next Article Durham scientists advance reactors in superconductor research

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Trending Posts

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.