The campaigns analyzed by Acronis TRU show how attackers evolve their compromise strategies, using compromised ScreenConnect installers, multiple RATs and new specially developed malware not present in public repositories
Acronis, global leader in the cybersecurity and in the data protection, presented the results of new research conducted by the Acronis Threat Research Unit (TRU), which highlights the intensification of attacks based on Trojan-containing versions of ConnectWise ScreenConnect.
Since March 2025, a significant increase in campaigns using this remote monitoring and management (RMM) tool to gain initial access to corporate networks has been observed, particularly in the United States. Attackers distribute ScreenConnect installers manipulated through social engineering techniques, often disguised as official or financial documents, exploiting users' trust in signed and apparently legitimate software.
The analyzes revealed a new distribution method via ClickOnce installers, which have no integrated configurations and are capable of recovering components at run time. This evolution reduces the effectiveness of static detection methods, complicating traditional defenses and leaving security teams with fewer reliable options to intercept the threat proactively.
Once installation is complete, attackers leverage ScreenConnect's automation features to simultaneously deploy two Remote Access Trojans (RATs). In addition to AsyncRAT, which is widely known and widespread in cybercrime, a new RAT developed in PowerShell was detected. The latter is distinguished by system reconnaissance capabilities, data exfiltration capabilities via Microsoft.XMLHTTP and a large set of obfuscation techniques, which include the use of dynamic aliases, hardcoded scripts and AMSI bypass. The simultaneous use of two RATs suggests possible scenarios of redundancy - i.e. the desire to maintain access even if one of the tools is detected or blocked -, the experimentation of customized tools or the sharing of the infrastructure between multiple criminal groups.
The observed campaigns also demonstrate a high ability to adapt on the part of the attackers. Within a few weeks, the same operators introduced new infection chains based on batch loaders and VBS, used to distribute updated variants of AsyncRAT. Subsequently, the release of PureHVNC RAT was also documented, distributed via process hollowing techniques, which allows silent remote control of compromised machines.
At the same time, the infrastructure investigation highlighted the reuse of pre-configured Windows Server 2022 virtual machines, with recurring hostnames, used in multiple campaigns and hosted on different IP addresses. This approach allows attackers to quickly reactivate their malicious servers and maintain operational continuity, reducing setup time in new campaigns.
“Attacks that exploit legitimate RMM tools like ScreenConnect represent a growing threat to enterprises, combining the reliability of recognized software with sophisticated distribution techniques that make them difficult to detect,” explains Eliad Kimhy, Sr. Security Researcher at Acronis TRU and author of the research.
The research highlights the need for organizations to carefully monitor the use of RMM tools, audit ScreenConnect installations, and implement defensive strategies capable of blocking suspicious communications to malicious domains.






