by TINTSWALO BALOYI
JOHANNESBURG, (CAJ News) – CYBERSECURITY experts at Kaspersky have identified a large-scale malicious campaign using counterfeit software websites to distribute a remote administration tool, ScreenConnect, ultimately enabling attackers to install the AsyncRAT trojan on victims’ devices.
The operation spans more than 90 fraudulent domains across 10 languages, including English, Arabic, Spanish, Chinese, German, Portuguese and Russian, suggesting a coordinated effort to target both individual users and organisations worldwide.
Researchers say the campaign affects Windows systems and relies heavily on search engine optimisation to push malicious sites to the top of search results.
According to Kaspersky, the activity was first detected through its Managed Detection and Response service, which uncovered fake websites impersonating popular software products such as OBS Studio, DNS Jumper, DS4Windows, Glary Utilities and Bandicam.
Users searching for free downloads were directed to these convincing replicas, where they unknowingly downloaded infected installers.
Instead of legitimate software, victims received a hidden version of ScreenConnect, a remote administration tool that grants attackers persistent access to compromised systems.
This access is then used to deploy AsyncRAT, an open-source trojan capable of full system control, including data theft and surveillance.
Domain registration activity linked to the campaign reportedly peaked in February 2026. Kaspersky also noted that in 2025 the same threat actor used similar tactics to disguise malicious files as gaming software, indicating an evolving and persistent operation.
The infection chain involves malicious archive files containing a legitimate, digitally signed Microsoft executable alongside a malicious DLL file.
The DLL is executed through a technique known as DLL sideloading, which allows the attacker to load malicious code while appearing legitimate to security systems.
“The campaign targets both users downloading free utilities from the Internet and corporate networks, where remote access tools are often allowlisted and granted elevated privileges,” said Denis Kulik, Lead SOC Analyst at Kaspersky.
“Its danger lies in its ability to enable large-scale credential theft and unauthorised system access, with stolen data often resold on dark web forums.”
Kaspersky has urged organisations to enforce strict software installation policies, monitor for unauthorised remote administration tools, and filter outbound traffic to unknown domains.
The company also recommends continuous employee awareness training and enhanced threat intelligence monitoring through security solutions such as its Managed Detection and Response platform.
For individual users, Kaspersky advises downloading software only from trusted sources, enabling multi-factor authentication, regularly checking accounts for suspicious activity, and verifying website authenticity before downloading any files.
– CAJ News
