Close Menu
TechurzTechurz
    What's Hot

    Quartermaster is building a maritime hive mind

    May 20, 2026

    From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

    May 19, 2026

    ‘Survivor’ stars Kyle Fraser and Kamilla Karthigesu introduce a goal-tracking app, Paprclip

    May 19, 2026
    Facebook X (Twitter) Instagram
    Tech Pulse
    • Quartermaster is building a maritime hive mind
    • From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing
    • ‘Survivor’ stars Kyle Fraser and Kamilla Karthigesu introduce a goal-tracking app, Paprclip
    • Forget the feed: Status AI raises $17M to turn social media into interactive entertainment
    • Stilta raises $10.5M from a16z and YC to help companies rediscover the patents they forgot they had
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    TechurzTechurz
    Home - Cyber Reality - AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto
    Cyber Reality

    AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

    TechurzBy TechurzSeptember 11, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Sep 11, 2025Ravie LakshmananMalware / Credential Theft

    Cybersecurity researchers have disclosed details of a new campaign that leverages ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) software, to deliver a fleshless loader that drops a remote access trojan (RAT) called AsyncRAT to steal sensitive data from compromised hosts.

    “The attacker used ScreenConnect to gain remote access, then executed a layered VBScript and PowerShell loader that fetched and ran obfuscated components from external URLs,” LevelBlue said in a report shared with The Hacker News. “These components included encoded .NET assemblies ultimately unpacking into AsyncRAT while maintaining persistence via a fake ‘Skype Updater’ scheduled task.”

    In the infection chain documented by the cybersecurity company, the threat actors have been found to leverage a ScreenConnect deployment to initiate a remote session and launch a Visual Basic Script payload via hands-on-keyboard activity.

    “We saw trojanized ScreenConnect installers masquerading as financial and other business documents being sent via phishing emails,” Sean Shirley, LevelBlue MDR SOC Analyst, told The Hacker News.

    The script, for its part, is designed to retrieve two external payloads (“logs.ldk” and “logs.ldr”) from an attacker-controlled server by means of a PowerShell script. The first of the two files, “logs.ldk,” is a DLL that’s responsible for writing a secondary Visual Basic Script to disk, using it to establish persistence using a scheduled task by passing it off as “Skype Updater” to evade detection.

    This Visual Basic Script contains the same PowerShell logic observed at the start of the attack. The scheduled task ensures that the payload is automatically executed after every login.

    The PowerShell script, besides loading “logs.ldk” as a .NET assembly, passes “logs.ldr” as input to the loaded assembly, leading to the execution of a binary (“AsyncClient.exe”), which is the AsyncRAT payload with capabilities to log keystrokes, steal browser credentials , fingerprint the system, and scan for installed cryptocurrency wallet desktop apps and browser extensions in Google Chrome, Brave, Microsoft Edge, Opera, and Mozilla Firefox.

    All this collected information is eventually exfiltrated to a command-and-control (C2) server (“3osch20.duckdns[.]org”) over a TCP socket, to which the malware beacons in order to execute payloads and receive post-exploitation commands. The C2 connection settings are either hard-coded or pulled from a remote Pastebin URL.

    “Fileless malware continues to pose a significant challenge to modern cybersecurity defenses due to its stealthy nature and reliance on legitimate system tools for execution,” LevelBlue said. “Unlike traditional malware that writes payloads to disk, fileless threats operate in memory, making them harder to detect, analyze, and eradicate.”

    AsyncRAT ConnectWise credentials Crypto exploits ScreenConnect steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTed Cruz’s new bill would let AI companies set their own rules for up to 10 years
    Next Article NASA Rover Finds Compelling Clues In Rock Sample
    Techurz
    • Website

    Related Posts

    Opinion

    Welcome to the post-hype crypto market

    February 25, 2026
    Cyber Reality

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 2025
    Cyber Reality

    Perplexity’s new AI tool lets you search patents with natural language – and it’s free

    November 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn
    Latest Reviews

    Techurz is a future-first technology publication covering AI systems, cyber reality, future tech, disruption, and digital signals — written today, searched tomorrow.

    Useful Links
    • Affiliate Disclosure
    • Terms and Conditions
    • Privacy Policy
    • Cookie Policy
    • Write For Us
    • About Us
    • Contact Us
    USEFUL LINKS
    • Our Authors / Editorial Team
    • Advertise
    • Disclaimer
    • DMCA
    • Editorial Policy
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Get sharp weekly signals on the technologies, risks, tools, and shifts that matter before they become obvious.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.