Home
About us
Articles
TRU Events
Acronis.com
TRU Security
Updates from Acronis Threat Research Unit
Home
About us
Articles
TRU Events
Acronis.com
Trojanized ScreenConnect installers evolve, dropping multiple RATs on a single machine
Over the past months, Acronis TRU (Threat Research Unit) has identified multiple active and ongoing campaigns leveraging trojanized versions of ConnectWise ScreenConnect to gain initial access to victim networks and compromise target machines.
Insights
August 21, 2025
— 5 min read
MSP cybersecurity news digest, August 13, 2025
Clinical data stolen in cyberattack on dialysis provider DaVita, Chanel, Pandora, Google and Cisco...
August 18, 2025
— 4 min read
MSP cybersecurity news digest, August 4, 2025
Scattered Spider group disrupted, but imitators carry on, Fake OAuth apps and Tycoon phishing kit used...
August 11, 2025
— 3 min read
Acronis Cyberthreats Update, August 2025
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis...
August 05, 2025
— 4 min read
MSP cybersecurity news digest, July 29, 2025
Benign-appearing panda images used by new Koske Linux malware to deliver malicious code, Turkish...
August 04, 2025
— 19 min read
MSPs a top target for Akira and Lynx ransomware
Acronis Threat Research Unit (TRU) analyzed recent samples of Akira and Lynx ransomware families to...
July 24, 2025
— 4 min read
MSP cybersecurity news digest, July 14, 2025
SafePay inflicts major ransomware attack on Ingram Micro, Oyster malware loader spread through SEO...
July 16, 2025
— 4 min read
MSP cybersecurity news digest, July 7, 2025
Zurich nonprofit Radix hit by Sarcoma ramsomware group, resulting in theft of 1.3TB of data, Google...
July 14, 2025
— 3 min read
Acronis Cyberthreats Update, July 2025
The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis...
June 30, 2025
— 4 min read
MSP cybersecurity news digest, June 30, 2025
ConnectWise ScreenConnect installer exploited by authenticode stuffing technique, attackers breach...
Trends and analysis
May 04, 2023
— 9 min read
Raccoon Stealer: A popular and dangerous threat
Raccoon Stealer, also known as Mohazo or Racealer, is an info-stealer malware that first appeared in...
April 28, 2023
— 9 min read
Malware with a “Money Message”
The purpose of Money Message ransomware is to encrypt files on a targeted computer, rendering the...
April 26, 2023
— 5 min read
Maui: An active and dangerous data wiper
Maui is a wiper that is designed to delete or overwrite data on a computer or digital device, causing...
March 29, 2023
— 9 min read
SwiftSlicer: A simple yet dangerous data wiper
On January 25, 2023, ESET Research found a new data wiper in the network of Ukrinform, Ukraine’s...
March 06, 2023
— 15 min read
IcedID (BokBot): From banking trojan to backdoor
IcedID, also known as BokBot, was initially a banking trojan when it was discovered in 2017. Now it is...
February 13, 2023
— 7 min read
CaddyWiper makes Windows machines unusable
CaddyWiper is an example of data-wiping malware, whose purpose is to corrupt the operating system and...
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
Deutsch
English
Español
Francais
Italiano
日本語
Dutch
Português
Svenska
No data