Bandicam Company A.I CyberSecurity Scoring
Bandicam Company
Company Information
Website:https://www.bandicam.com
Employees number:6
Number of followers:93
NAICS:5112
Industry Type:Software Development
Homepage:bandicam.com
Bandicam Company Risk Score (AI oriented)
Between 700 and 749
Bandicam CompanySoftware Development
Updated:
01/07/2026
01/07/2026
736/1000
Moderate
Ba
Bandicam Company Global Score (TPRM)
xxxx
Bandicam CompanySoftware Development
Score locked

Bandicam CompanyModerate
Current Score
736Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
736
JULY 2026
736
JUNE 2026
736
MAY 2026
735
APRIL 2026
734
MARCH 2026
752
Cyber Attack
01 Mar 2026 • Bandicam Company
Bandicam, ScreenConnect and OBS Studio: How a single ScreenConnect incident exposed a massive campaign
Cybercriminals Exploit Legitimate Remote Access Tool in Large-Scale Malware Campaign
733
CRITICAL-19
BANOBSCON1782901541
Cybercriminals Exploit Legitimate Remote Access Tool in Large-Scale Malware Campaign
In a recent investigation, Kaspersky’s Managed Detection and Response (MDR) team uncovered a sophisticated cyberattack leveraging ScreenConnect, a legitimate remote monitoring tool, to deploy AsyncRAT malware. The campaign, active since October 2025, spans over 90 spoofed domains in 10 languages, targeting users worldwide through typosquatted websites impersonating popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.
### How the Attack Works
1. Initial Compromise
- Victims unknowingly download malicious installers from fraudulent websites ranking high in search engine results due to SEO manipulation.
- The downloaded archives (e.g., obs-studio-windows-x64.zip) contain a legitimate Microsoft-signed *install.exe alongside a malicious install.res.1033.dll* library.
- Upon execution, the DLL sideloads ScreenConnect, installing it silently via msiexec.exe under the guise of a "Microsoft Update Service."
2. Post-Exploitation Tactics
- ScreenConnect deploys PowerShell and VBS scripts to:
- Disable Microsoft Defender by excluding critical directories (C:\, C:\Users\Public).
- Turn off User Account Control (UAC) by modifying registry keys.
- Terminate running PowerShell processes to evade detection.
- A VBScript (*installer_method3_stream.vbs*) drops five files in C:\Users\Public, including secret_bytes.txt, which contains an XOR-encrypted AsyncRAT payload.
- The malware uses process hollowing to inject AsyncRAT into RegAsm.exe, a trusted Windows process, and establishes persistence via a scheduled task (*MasterPackager.Updater*) that re-executes every two minutes.
3. Command-and-Control (C2) Infrastructure
- AsyncRAT connects to mora1987[.]work[.]gd and other C2 domains.
- ScreenConnect’s C2 servers (e.g., r.servermanagemen[.]xyz) are embedded in system.config XML files within the MSI packages.
### Campaign Scale & Infrastructure
- Spoofed Websites: Over 90 domains mimic software vendors, hosted across three IP clusters (U.S. and Germany).
- Cluster 1 (162.216.241[.]242, 198.23.185[.]81): Initially used for gaming-themed lures, later shifted to freeware impersonation.
- Cluster 2 (2.59.134[.]97): Focused exclusively on fake software portals.
- Global Reach: Domains localized in English, Russian, Chinese, German, French, Spanish, and Arabic, indicating a broad targeting strategy.
- SEO Abuse: Fraudulent sites appear at the top of search results for queries like "OBS Studio download," increasing victim exposure.
### Impact & Objectives
- Targets: Both individual users and corporate networks, where remote access tools are often allowlisted.
- Goal: Likely credential theft and unauthorized system access, with compromised endpoints potentially resold on dark web marketplaces.
- Persistence: The attack chain ensures long-term control over infected devices via ScreenConnect and AsyncRAT.
### Detection & Indicators
Kaspersky’s MDR detected the attack through:
- ScreenConnect service creation with suspicious parameters.
- Anomalous child processes (e.g., powershell.exe, schtasks.exe) spawned by ScreenConnect.
- Malware signatures (e.g., Trojan.Win64.DLLhijack., Trojan.VBS.Agent.).
Key IOCs:
- Malicious DLL: install.res.1033.dll (MD5: 5F96C04E3AFAE97017B201BE112284D2).
- C2 Domains: mora1987[.]work[.]gd, servermanagemen[.]xyz.
- Fake Websites: studioobs[.]com, dnsjumper[.]app, ds4windows[.]pro.
The campaign highlights the risks of trusted remote tools and typosquatting, underscoring the need for strict software controls and outbound traffic monitoring. Many fraudulent domains remain active as of publication.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Bandicam Company ??
What was Bandicam Company's A.I Rankiteo Cyber Score in July 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in June 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in May 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in April 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in March 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in February 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in January 2026 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in December 2025 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in November 2025 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in October 2025 ??
What was Bandicam Company's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Bandicam Company's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Bandicam Company ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Bandicam Company's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?