Home
About us
Articles
TRU Events
Acronis.com
TRU Security
Updates from Acronis Threat Research Unit
Home
About us
Articles
TRU Events
Acronis.com
Trojanized ScreenConnect installers evolve, dropping multiple RATs on a single machine
Over the past months, Acronis TRU (Threat Research Unit) has identified multiple active and ongoing campaigns leveraging trojanized versions of ConnectWise ScreenConnect to gain initial access to victim networks and compromise target machines.
Insights
August 21, 2025
— 5 min read
MSP cybersecurity news digest, August 13, 2025
Clinical data stolen in cyberattack on dialysis provider DaVita, Chanel, Pandora, Google and Cisco...
August 18, 2025
— 4 min read
MSP cybersecurity news digest, August 4, 2025
Scattered Spider group disrupted, but imitators carry on, Fake OAuth apps and Tycoon phishing kit used...
August 11, 2025
— 3 min read
Acronis Cyberthreats Update, August 2025
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis...
August 05, 2025
— 4 min read
MSP cybersecurity news digest, July 29, 2025
Benign-appearing panda images used by new Koske Linux malware to deliver malicious code, Turkish...
August 04, 2025
— 19 min read
MSPs a top target for Akira and Lynx ransomware
Acronis Threat Research Unit (TRU) analyzed recent samples of Akira and Lynx ransomware families to...
July 24, 2025
— 4 min read
MSP cybersecurity news digest, July 14, 2025
SafePay inflicts major ransomware attack on Ingram Micro, Oyster malware loader spread through SEO...
July 16, 2025
— 4 min read
MSP cybersecurity news digest, July 7, 2025
Zurich nonprofit Radix hit by Sarcoma ramsomware group, resulting in theft of 1.3TB of data, Google...
July 14, 2025
— 3 min read
Acronis Cyberthreats Update, July 2025
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis...
June 30, 2025
— 4 min read
MSP cybersecurity news digest, June 30, 2025
ConnectWise ScreenConnect installer exploited by authenticode stuffing technique, attackers breach...
Trends and analysis
October 25, 2023
— 18 min read
Ursnif, the banking trojan
Ursnif, also known as Gozi or Dreambot, is a banking trojan. Ursnif is typically delivered via...
October 17, 2023
— 16 min read
Nokoyawa ransomware takes evasive action, leaves...
Nokoyawa ransomware was first discovered in February 2022, and it initially shared similarities to the...
October 06, 2023
— 4 min read
Acronis Cyberthreats Update, October 2023
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis...
October 02, 2023
— 9 min read
BlackByte 3.0 uses vulnerable drivers to compromise systems
BlackByte is an example of ‘ransomware-as-a-service‘ (RaaS), and the threat actors behind it...
September 08, 2023
— 4 min read
Acronis Cyberthreats Update, September 2023
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis...
August 08, 2023
— 8 min read
Acronis Cyberthreats Report, August 2023
The Acronis Cyberthreats Report covers current cyberthreat activity and trends, as observed by Acronis...
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
Deutsch
English
Español
Francais
Italiano
日本語
Dutch
Português
Svenska
No data