{"id":7081,"date":"2025-09-20T10:04:10","date_gmt":"2025-09-20T10:04:10","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/20\/threat-actors-selling-new-undetectable-rat-as-screenconnect-fud-alternative\/"},"modified":"2025-09-20T10:04:10","modified_gmt":"2025-09-20T10:04:10","slug":"threat-actors-selling-new-undetectable-rat-as-screenconnect-fud-alternative","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/20\/threat-actors-selling-new-undetectable-rat-as-screenconnect-fud-alternative\/","title":{"rendered":"Threat Actors Selling New Undetectable RAT as \u2019ScreenConnect FUD Alternative\u2019"},"content":{"rendered":"<p>    Threat Actors Selling New Undetectable RAT as \u2019ScreenConnect FUD Alternative\u2019<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A threat actor has been observed advertising a new Remote Access Trojan (RAT) on underground forums, marketing it as a fully undetectable (FUD) alternative to the legitimate remote access tool, <a href=\"https:\/\/cybersecuritynews.com\/tag\/screenconnect-security-flaw-let-attackers-by\/\" target=\"_blank\" rel=\"noreferrer noopener\">ScreenConnect<\/a>.<\/p>\n<p>The malware is being sold with a suite of advanced features designed to bypass modern security defenses, signaling a growing trend in sophisticated, ready-to-use <a href=\"https:\/\/cybersecuritynews.com\/cybercrime-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybercrime tools<\/a>.<\/p>\n<p>The seller claims the tool achieves zero detections during both static and runtime analysis, making it a potent threat for initial access and payload delivery operations. <\/p>\n<p>This development underscores the ongoing efforts by malicious actors to exploit trust and evade detection by mimicking legitimate software and processes.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-bypassing-security-with-advanced-evasion\"><strong>Bypassing Security With Advanced Evasion<\/strong><\/h2>\n<p>The primary selling point of this new RAT is its ability to bypass security warnings from both <a href=\"https:\/\/cybersecuritynews.com\/hackers-mimic-google-chrome-install-page\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Chrome<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/windows-smartscreen-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows SmartScreen<\/a>.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhiRixxWlKDchkr8rIgn6zXylED-CBdtHZ4lx2RDN1M5pJ9HeKEHTQA6ERg-NsQBGXwqNjb6z9JzYmOkjBBozVTvJnbAkoay-axN_I0yAkd5NQ1bAH3f-KMvnkYEouJ-ugXcFKjTa5aCsmEQC3s2olTBEnKneof6j-TLy2KsR6LtsqAUCs0_IgIpVdiQroE\/s16000\/Malware%2520Advertised.webp?ssl=1\" alt=\"FUD Malware Claim\"><figcaption class=\"wp-element-caption\">FUD Malware Claim<\/figcaption><\/figure>\n<p>The threat actor claims this is achieved by bundling the malware with a valid Extended Validation (EV) certificate. <\/p>\n<p>EV certificates are a high-assurance digital identity standard that typically causes browsers to display a green bar or the company\u2019s name, instilling a false sense of security in the victim. <\/p>\n<p>The package also includes antibot mechanisms and cloaked landing pages. These features allow the malware to present benign content to <a href=\"https:\/\/cybersecuritynews.com\/web-security-scanners\/\" target=\"_blank\" rel=\"noreferrer noopener\">security scanners<\/a> and sandboxes while delivering the malicious payload to genuine targets, a common tactic for evading automated analysis.<\/p>\n<p>The provided advertisement showcases a convincing but fraudulent Adobe Acrobat Reader download page, demonstrating a typical <a href=\"https:\/\/cybersecuritynews.com\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> scheme for delivery.<\/p>\n<p>According to the seller\u2019s post, the RAT is equipped with a remote viewer, granting the attacker direct visual control over a compromised machine\u2019s desktop. <\/p>\n<p>This capability allows for real-time monitoring, data exfiltration, and interactive system manipulation. Furthermore, the tool utilizes a PowerShell-based command to load its executable. This fileless technique helps it remain hidden from traditional <a href=\"https:\/\/cybersecuritynews.com\/best-ransomware-protection-solutions\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus solutions<\/a> that primarily focus on scanning files on disk.<\/p>\n<p>The actor explicitly states the tool can be used as a \u201cFUD loader,\u201d indicating its primary function may be to establish a persistent and stealthy foothold on a target system before deploying secondary payloads, such as ransomware, spyware, or banking trojans. <\/p>\n<p>The seller offers a demo and promises delivery within 24 working hours, suggesting a professional and operationalized service.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fud-as-screenconnect\/\">Threat Actors Selling New Undetectable RAT as \u2019ScreenConnect FUD Alternative\u2019<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fud-as-screenconnect\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Selling New Undetectable RAT as \u2019ScreenConnect FUD Alternative\u2019 A threat actor has been observed advertising a new Remote Access Trojan (RAT) on underground forums, marketing it as a fully undetectable (FUD) alternative to the legitimate remote access tool, ScreenConnect. The malware is being sold with a suite of advanced features designed to bypass [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7081","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7081"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7081"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7081\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}