SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025
A search engine optimization poisoning campaign has been targeting Windows users since October 2025. This campaign involves trojanized installers for over 25 popular software applications, leading to the installation of AsyncRAT, a remote access trojan.
A search engine optimization poisoning campaign has been targeting Windows users since October 2025. This campaign involves trojanized installers for over 25 popular software applications, leading to the installation of AsyncRAT, a remote access trojan.
The operation was uncovered in March 2026 after running undetected for approximately five months. Investigations revealed a multi-stage infection chain that silently compromises machines and exfiltrates sensitive data.
The campaign uses fake software download pages that are pushed to the top of search engine results. Users searching for tools such as VLC Media Player, OBS Studio, KMS Tools, and CrosshairX are targeted. Upon clicking a download link, victims receive a ZIP archive containing both legitimate software and a hidden malicious component.
The lure sites use fake Schema.org aggregate ratings and hreflang tags to appear credible. The campaign infrastructure includes three ScreenConnect relay hosts and two payload delivery backends. Over 100 malicious files were identified on VirusTotal.
The final payload is AsyncRAT, an open-source remote access trojan. It includes additional features such as a keylogger, clipboard monitor, cryptocurrency clipper for 16 currencies, and a dynamic plugin system. This build, internally referred to as "FlowProxy Monitor V3," incorporates a geo-fencing mechanism that bypasses cryptocurrency interception for specific regions.
A search engine optimization poisoning campaign has been targeting Windows users since October 2025.
Initially, payloads were hosted at static URLs. By late January 2026, the operator switched to a randomized token-based system, making URL-based blocking ineffective. The primary delivery backend disguises itself as a file-sharing site but serves malicious installers exclusively.
The infection begins when the victim executes the downloaded file. The ZIP archive includes a genuine VLC installer and a malicious libvlc.dll, utilizing DLL sideloading to run the attacker's code. The malicious DLL extracts a hidden MSI installer that deploys ScreenConnect as a Windows service, reaching the attacker's relay server.
The campaign employs three persistence mechanisms to survive reboots and locked sessions:
A Windows service configured to start automatically A Windows Authentication Package loaded into LSASS A scheduled task re-executing the VBScript every two minutes
Users are advised to download software from official vendor websites and be cautious of unexpected elevation prompts. Security teams should monitor for unauthorized ScreenConnect deployments, process hollowing events in RegAsm.exe, and block identified lure domains and relay hosts.
For further details, refer to the full NCC Group report .
Based on reporting by Cyber Security News.
