ScreenConnect, also known as ConnectWise Control, is a legitimate commercial remote monitoring and management tool for Windows that is frequently abused by threat actors as an unauthorized remote-access implant. In malicious operations, attackers commonly deliver preconfigured ScreenConnect clients that automatically register to attacker-controlled relay infrastructure, giving operators interactive control of compromised systems while blending in with normal administrative software and reducing reliance on custom malware.
Abuse of ScreenConnect has been observed across multiple intrusion types, including phishing campaigns, fake software download portals, SEO-poisoning operations, cryptojacking activity, and post-exploitation persistence following exploitation of public-facing vulnerabilities or cloud account compromise. Delivery methods include phishing lures themed as software updates, meeting invitations, tax or document portals, and trojanized software installers. Several campaigns used DLL sideloading with legitimate signed binaries to silently install ScreenConnect alongside decoy software, while others delivered it through malicious scripts, MSI packages, or as a second-stage payload dropped by another remote management tool.
Once installed, attackers use ScreenConnect to establish persistent remote access, execute scripts, transfer files, and deploy additional malware. Documented follow-on activity includes installation of AsyncRAT, Quasar, cryptocurrency miners, and information-stealing payloads. In observed intrusions, ScreenConnect was used to launch PowerShell and VBScript components that weakened host defenses, modified Microsoft Defender exclusions, disabled User Account Control, created scheduled-task persistence, and supported process-hollowing chains for secondary payload execution. Because the software is legitimate and signed, its malicious use often evades simplistic malware-based detections and can be mistaken for authorized IT activity.
ScreenConnect abuse has been linked to a wide range of threat activity, including large-scale phishing ecosystems, financially motivated access operations, cryptojacking campaigns, ransomware precursor activity, and state-linked intrusion sets such as MERCURY as well as Storm-2949 activity involving customized ScreenConnect deployments. It has also appeared in campaigns targeting enterprise users, general consumers, taxpayers, and blockchain developers. In many cases, ScreenConnect serves as the durable foothold that enables broader objectives such as credential theft, data theft, lateral movement, resale of access, or eventual ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-47812 (CVSS skóre 10,0) Kritická zraniteľnosť sa nachádza vo webovom rozhraní servera a spočíva v nesprávnom spracovaní tzv. nulových bajtov ('\0') v rámci parametra username v koncovom bode loginok.html. Vzdialený neautentifikovaný útočník by ju mohol zneužiť na injekciu kódu v jazyku Lua do súborov používateľských relácií a následné vykonanie systémových príkazov s oprávneniami root (Linux) alebo NT AUTHORITY\SYSTEM (Windows).
First observed in February 2026, the STAC3725 campaign exploits the CitrixBleed2 vulnerability (CVE-2025-5777) to gain access and then installs a malicious ScreenConnect client to maintain persistence.
...Fortinet FortiClient EMS... exploited... The vulnerability in question is CVE-2023-48788... SQL injection...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation uses legitimate RMM software (primarily ConnectWise ScreenConnect) as its final payload, giving operators remote access to victim machines while avoiding the detection signatures associated with traditional malware.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
MERCURY operators include links to or directly attach commercial remote access tools, such as ScreenConnect, in these initial phishing mails.
The operator establishes endpoint persistence via two legitimately-signed RMMs deployed in parallel: ConnectWise ScreenConnect from attacker infrastructure at 185.241.208[.]243:9090 ... MALWARE ScreenConnect / ConnectWise (legitimate build abused via deployment vector), Evilconwi (Malpedia family alias for the Storm-2949 ScreenConnect variant)
In 2024, Proofpoint researchers observed a notable increase in the use of RMM tools from cybercriminal threat actors in documented campaigns, including using payloads such as ScreenConnect, Fleetdeck, and Atera.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
When we saw Screen Connect on 130 endpoints, we assumed it was there intentionally to support people working from home. It turned out the company knew nothing about it – the attackers had installed the software to ensure they could maintain access to the network and compromised devices.
A new phishing scam that presents a fake Bank of America message is being used by cybercriminals to gain remote control of victims’ users.
The attacker established persistent remote access with full system-level privileges, enabling command execution on the compromised endpoint
The unauthorized RMM agent, Bluetrait, used PowerShell to install a second, unauthorized remote access tool
While on the domain controller, the attackers created a new domain user ... cmd.exe /c net user svc_mail pass1234@ /add /domain ... Next the service account was added to the domain admins group.
When we saw Screen Connect on 130 endpoints, we assumed it was there intentionally to support people working from home. It turned out the company knew nothing about it – the attackers had installed the software to ensure they could maintain access to the network and compromised devices.
Each stage contains large Base64-encoded data blobs that decodes into additional scripts
initial access was identified as a file masquerading as a legitimate Adobe PDF Installer
If we can modify the application in such a way that EventLog.WriteEntry() is no longer ever executed, we can prevent the generation of event logs... This ensures that ScreenConnect can no longer generate any events and will create less evidence.
ConnectWise Control (among others) offers functionality to remotely: Execute arbitrary commands; Terminate processes; Uninstall software; View event logs; Start / Stop services; Install Windows updates. Additionally, ConnectWise Control allows an operator to take control of a machine's desktop session.
the attackers used Dridex to deliver additional malware ... and move laterally within the target’s network
ScreenConnect events are generated by the application itself, meaning that a determined attacker can prevent any logs from being created... patch the bytecode of ScreenConnect.Core.dll ... and overwrite the call to EventLog.WriteEntry().
536 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote monitoring and management / remote access software abused in this campaign for unauthorized remote access. Victims are socially engineered into installing preconfigured ScreenConnect clients that auto-register to attacker-controlled relay instances.
Legitimate remote administration software abused by attackers to gain remote access, run malicious scripts, weaken defenses, and deploy AsyncRAT. It is not malware by itself but is weaponized in this campaign.
Legitimate remote access tool abused as the initial access and persistence mechanism in the campaign. It is silently installed via DLL sideloading, registered as a service under a benign name, and used to connect the victim system to attacker-controlled infrastructure before deploying AsyncRAT.
Legitimate remote access software abused in this campaign as an intermediary payload and persistence/control mechanism to deploy and execute AsyncRAT on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.