Cybercriminals operate over 90 fake domains mimicking popular Windows software and use DLL sideloading with ScreenConnect as a bridge to the AsyncRAT trojan to steal remote access and credentials.
GhostTree exploits improperly guarded NTFS junctions in the Windows file system to trap scanners in infinite loops and hide malicious files from detection.