Researchers reported multiple campaigns using fake download and streaming sites to compromise users with remote access tools, malware, and proxyware. Kaspersky found more than 90 spoofed domains in 10 languages promoting bogus Windows software downloads through search engine optimization; the delivered archives used DLL sideloading to install the expected application alongside ScreenConnect, then deployed AsyncRAT for persistent access. In one investigated case, the attackers altered Microsoft Defender exclusions, disabled User Account Control, and used process hollowing into RegAsm.exe to launch the payload, creating risk for both consumers and enterprise networks because remote administration tools are often allowlisted and may run with elevated privileges.
A parallel set of campaigns abused demand for free media and utilities to lure victims into installing unwanted software that can expose systems and internet connections to criminal use. Researchers tracking World Cup-themed piracy sites found rotating mirror domains, typosquatting, and cloud-hosted pages pushing fake Stremio installers, VPN-themed lures, and affiliate-style downloads tied to malware, phishing, and scams. Separate analysis of a fake 7-Zip installer showed a Go-based backdoor that converted infected Windows hosts into residential proxy nodes, while broader threat reporting warned that free VPNs, streaming apps, browser extensions, and cheap IoT products are increasingly used to build residential proxy networks that criminals exploit for fraud, scraping, account abuse, and evasion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers identified a high-severity campaign exploiting interest in the 2026 FIFA World Cup through a large network of pirated sports-streaming websites. The operation used mirror domains, typosquatting, cloud-hosted pages, and domain rotation, and also pushed fake Stremio installers and VPN-themed lures.
The article reported that in 2026, 65% of Infoblox Threat Defense Cloud customers made DNS queries to domains associated with accessing or orchestrating residential proxy networks, totaling more than 500 billion queries per month. The activity was linked to abuse of consumer devices through free VPNs, streaming apps, browser extensions, and IoT products.
Researchers assessed that the ScreenConnect campaign appeared to pause by late March 2026, although many lure sites remained online. In investigated infections, attackers used ScreenConnect to deploy AsyncRAT and weaken host defenses.
Kaspersky said registrations of spoofed domains used in the ScreenConnect malware campaign peaked in February 2026. The broader operation used more than 90 domains in 10 languages and promoted them through SEO.
Researchers reported that in January 2026 the ScreenConnect campaign changed its lure strategy from fake game sites to free utility downloads. Victims were served malicious archives that silently installed both the expected software and ScreenConnect via DLL sideloading.
Kaspersky researchers said the infrastructure for a malware campaign abusing ScreenConnect began forming in October 2025. The operation later used spoofed domains and fake software-download sites to deliver ScreenConnect and AsyncRAT.
Analysis described a malware campaign in which a fake 7-Zip installer from 7zip[.]com deployed a Go-based Windows backdoor that turned infected hosts into residential proxy nodes. The trojanized installer was signed with a now-revoked JOZEAL NETWORK TECHNOLOGY CO., LIMITED certificate and established persistence and outbound connections to hero/smshero-themed infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecommunity.gurucul.com
Open sourcecysecurity.news
Open sourceblog.lukeacha.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.