
AsyncRAT Exploits ConnectWise ScreenConnect in New Cyberattack Campaign
Researchers in cybersecurity have uncovered a new campaign leveraging ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) tool, to deploy a fileless loader that installs the AsyncRAT remote access Trojan (RAT). The attackers utilize ScreenConnect to gain remote access and then execute a layered VBScript to deploy AsyncRAT, enabling them to steal sensitive data from compromised hosts. This attack vector highlights the growing trend of "living off the land," where malicious actors exploit legitimate software to bypass security measures. The use of ScreenConnect, a tool commonly whitelisted in enterprise environments, makes detection and prevention particularly challenging. To mitigate such threats, organizations should monitor and restrict the use of RMM tools, implement behavioral analysis to detect anomalous activities, and employ endpoint detection and response (EDR) solutions. This campaign underscores the importance of robust internal monitoring and response capabilities to counter sophisticated attacks that exploit trusted software.