Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025

A search engine optimization poisoning campaign has been targeting Windows users since October 2025. This campaign involves trojanized installers for over 25 popular software applications, leading to the installation of AsyncRAT, a remote access trojan.

A search engine optimization poisoning campaign has been targeting Windows users since October 2025. This campaign involves trojanized installers for over 25 popular software applications, leading to the installation of AsyncRAT, a remote access trojan.

The operation was uncovered in March 2026 after running undetected for approximately five months. Investigations revealed a multi-stage infection chain that silently compromises machines and exfiltrates sensitive data.

The campaign uses fake software download pages that are pushed to the top of search engine results. Users searching for tools such as VLC Media Player, OBS Studio, KMS Tools, and CrosshairX are targeted. Upon clicking a download link, victims receive a ZIP archive containing both legitimate software and a hidden malicious component.

The lure sites use fake Schema.org aggregate ratings and hreflang tags to appear credible. The campaign infrastructure includes three ScreenConnect relay hosts and two payload delivery backends. Over 100 malicious files were identified on VirusTotal.

The final payload is AsyncRAT, an open-source remote access trojan. It includes additional features such as a keylogger, clipboard monitor, cryptocurrency clipper for 16 currencies, and a dynamic plugin system. This build, internally referred to as "FlowProxy Monitor V3," incorporates a geo-fencing mechanism that bypasses cryptocurrency interception for specific regions.

A search engine optimization poisoning campaign has been targeting Windows users since October 2025.
نضال النعيم · Thehackingpost

Initially, payloads were hosted at static URLs. By late January 2026, the operator switched to a randomized token-based system, making URL-based blocking ineffective. The primary delivery backend disguises itself as a file-sharing site but serves malicious installers exclusively.

The infection begins when the victim executes the downloaded file. The ZIP archive includes a genuine VLC installer and a malicious libvlc.dll, utilizing DLL sideloading to run the attacker's code. The malicious DLL extracts a hidden MSI installer that deploys ScreenConnect as a Windows service, reaching the attacker's relay server.

The campaign employs three persistence mechanisms to survive reboots and locked sessions:

A Windows service configured to start automatically A Windows Authentication Package loaded into LSASS A scheduled task re-executing the VBScript every two minutes

Advertisement

Users are advised to download software from official vendor websites and be cautious of unexpected elevation prompts. Security teams should monitor for unauthorized ScreenConnect deployments, process hollowing events in RegAsm.exe, and block identified lure domains and relay hosts.

For further details, refer to the full NCC Group report .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories