ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
I received a very simple phishing email:
From: contact@mejuri[.]com To: <redacted> Subject: EFT Wire Transfer Paid Invoice Receipt Dear Customer, Payment of $5745.65 was Received. Please click here to view your Order Information in PDF If this charge wasn't authorized by you, contact our customer service to cancel and receive an immediate refund. Digitally Yours, Customer Support: +1(332)638474823
“Click here” is a link pointing to:
hxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe
This email passed all the basic security controls. The link points to a real PE file. Today this attack vector will be blocked by browsers because downloaded an executable is suspicious!
The PE file was unknown on VT so I did a quick analysis of it. It’s a legit application: a ScreenConnect[1] client preconfigured to call-back a test account operated by the Attacker. Here is the configuration extracted from the PE file:
|
Parameter |
Value |
|
Relay (h) |
instance-v2e3e2-relay.screenconnect.com |
|
Port (p) |
443 |
|
Instance ID |
v2e3e2 (ConnectWise-hosted cloud) |
|
Instance key (k) |
RSA-2048 public key, blob SHA256 16b1cec1…9b00ead7 |
The PE is signed by ConnectWise, LLC (DigiCert G4 Code Signing CA1). The Authenticode digest matches the signed digest exactly. There's no overlay and nothing appended to or injected into the certificate table, so the signed-but-tampered config trick isn't used here.
Such tools are a gold mine for attackers because they are easy to deploy and trusted by most used! The list of “RMM” (Remote Monitoring and Management) tools is huge. Here is a brief list of the well-known ones;
- ScreenConnect
- AnyDesk
- TeamViewer
- LogMeIn
- Bomgar (BeyondTrust Remote Support)
- Zoho Assist
- Remote utilities like rutserv.exe
- NetSupport Manager
- SimpleHelp
If you want a better overview, check LOLRMM project [2] that maintains a list similar to the LOLBAS project!
[1] https://www.screenconnect.com
[2] https://lolrmm.io
Xavier Mertens (@xme)
Senior ISC Handler | SANS Principal Instructor | Freelance Consultant
Xameco | PGP Key
Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-01 05:32 UTC
Related stories
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
The Hacker News · 2026-10-02
- Microsoft says threat actors are ahead in the early AI race
BleepingComputer · 2026-10-01
- Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
The Record · 2026-10-01
- State-linked actor targets US AI policy experts in credential phishing campaigns
Cybersecurity Dive · 2026-10-01
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
The Hacker News · 2026-10-01