ConnectWise ScreenConnect is legitimate remote-support and remote monitoring and management software frequently abused to obtain unauthorized control of Windows endpoints. It is not inherently malware. Attackers deploy preconfigured clients connected to infrastructure they control, enabling interactive screen control, command and script execution, file transfer, and continued access to compromised systems. Observed users include Magnet Goblin, Qilin ransomware affiliates, and the CSuite phishing operation. Abuse has affected enterprise endpoints and restaurant point-of-sale environments.
Unauthorized installations are delivered through phishing links, document-sharing lures, fraudulent technical-support interactions, and counterfeit Adobe Reader or collaboration-software updates. Campaigns have abused legitimate Microsoft Power BI dashboards and other trusted hosting services to direct victims to attacker-controlled download pages. ScreenConnect has also been deployed after exploitation of public-facing applications, including Fortinet FortiClient EMS and NCR Aloha management software. Windows-service installations provide persistence, and attackers frequently install multiple clients or additional remote-management products to preserve redundant access. Remote sessions have been used to deploy further payloads and tools that conceal interactive activity.
Trojanized ScreenConnect clients have additionally exhibited worm-like propagation by automatically transferring and executing VBScript stages on newly connected ScreenConnect endpoints. These stages profile installed security software and host characteristics, select encrypted payloads, and launch PowerShell-based follow-on components. Associated payload packages can establish user-level backdoors and startup persistence, bypass UAC, weaken Microsoft Defender protections, and deploy tunneling utilities or XMRig. These malicious modifications and accompanying payloads are distinct from the legitimate product's normal functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Downloaded .msi files were typically either Atera or ScreenConnect, which could provide adversaries with remote access to affected devices.
The TrendAI Vision One MDR team has been observing the recurring abuse of ConnectWise ScreenConnect, a legitimate and code-signed remote-support (RMM) tool. This involves using ScreenConnect as a covert remote-access tool (RAT) spanning different intrusions, different victims, and separate infrastructure.
The TrendAI Vision One MDR team has been observing the recurring abuse of ConnectWise ScreenConnect, a legitimate and code-signed remote-support (RMM) tool. This involves using ScreenConnect as a covert remote-access tool (RAT) spanning different intrusions, different victims, and separate infrastructure.
CVE-2025-47812 (CVSS skóre 10,0) Kritická zraniteľnosť sa nachádza vo webovom rozhraní servera a spočíva v nesprávnom spracovaní tzv. nulových bajtov ('\0') v rámci parametra username v koncovom bode loginok.html. Vzdialený neautentifikovaný útočník by ju mohol zneužiť na injekciu kódu v jazyku Lua do súborov používateľských relácií a následné vykonanie systémových príkazov s oprávneniami root (Linux) alebo NT AUTHORITY\SYSTEM (Windows).
First observed in February 2026, the STAC3725 campaign exploits the CitrixBleed2 vulnerability (CVE-2025-5777) to gain access and then installs a malicious ScreenConnect client to maintain persistence.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor’s Windows tools appear to include popular Remote Monitoring & Management tools (RMM) software ScreenConnect, which is downloaded from the attacker-controlled server.
One Qilin affiliate using Atera to deploy AnyDesk, with ScreenConnect alongside it for redundancy.
« déploiement d’outils légitimes de gestion (ScreenConnect, Action1, Atera, Syncro, PDQ Connect) renommés en Adobe, Dotloop, DocuSign » ; des installeurs ScreenConnect étaient hébergés sur GitHub.
The operation uses legitimate RMM software (primarily ConnectWise ScreenConnect) as its final payload, giving operators remote access to victim machines while avoiding the detection signatures associated with traditional malware.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The actor executed 'several SQL injections with obfuscated commands'; the TTP table specifies 'Use of CHAR() on SQL injection payloads.'
Follow-on tooling used filenames that closely resembled legitimate Windows, Microsoft Defender, security, and Phone Link applications.
PowerShell and ScreenConnect communicated with actor-controlled infrastructure over HTTP/HTTPS.
Multiple cloud-hosted web services were used throughout the delivery and command-and-control infrastructure.
Transfer of files from the attacker to the environment through legitimate applications.
761 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
83 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote-access software maintained alongside AnyDesk by a Qilin affiliate to provide redundant remote access.
Legitimate remote management software explicitly abused in this campaign for persistent attacker access. Phishing pages fingerprint visitors and download a ScreenConnect installer. Attackers deploy a second client connected to separate infrastructure; in one incident, a PowerShell script installed the second client and removed the first, likely to evade detection. A scheduled task reran that script every two minutes.
Legitimate remote management software explicitly abused in this campaign, rather than an inherently malicious family. Phishing pages delivered an attacker-controlled ScreenConnect client that installed a second client connected to separate infrastructure. In one incident, a PowerShell script removed the first instance after deploying the second, likely to evade detection. Multiple clients provided persistent remote access.
Legitimate remote-access software explicitly weaponized in the phishing campaign. Victims are directed through a deceptive Power BI page to attacker-controlled sites that automatically download a ScreenConnect installer. Two unauthorized clients are deployed; the first is subsequently uninstalled to reduce visibility. Campaign activity was observed beginning September 10, 2026, but the content does not establish the software's first discovery date.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.