LIVE · cybersecurity feed
Live wire

remote access trojan

screenconnecthigh

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

Threat actors are distributing malicious installer archives that masquerade as popular freeware, such as OBS Studio and Bandicam. These installers contain a legitimate Microsoft binary alongside a rogue DLL that enables DLL sideloading. This process deploys the ScreenConnect remote access tool, which attackers use to maintain control over compromised systems and potentially execute further payloads like AsyncRAT.