Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

0
Medium
Published: 08/04/2026 (08/04/2026, 18:20:59 UTC)
Source: AlienVault OTX General

Description

Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 11:28:32 UTC

Technical Analysis

This campaign involves threat actors deploying ScreenConnect RMM agents through social engineering lures and multiple delivery mechanisms including VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages. Payloads are retrieved from a WsgiDAV staging server (207.174.0.143:8080) and are signed legitimate ConnectWise ScreenConnect MSIs, enabling evasion of security controls that trust signed code. The installed ScreenConnect agents beacon to attacker-controlled relay servers, providing persistent remote access. The campaign has evolved from obfuscated VBScript with XOR encryption to aggressive .NET loaders that execute complex Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. The threat actor actively rotates payload hashes and uses stealth tactics to avoid detection and maintain persistence.

Potential Impact

Successful exploitation results in the silent installation of ScreenConnect RMM agents that provide attackers with persistent remote access to compromised systems. The use of legitimate signed software allows the payloads to bypass many security controls, increasing the likelihood of successful compromise. The campaign targets both Windows and macOS platforms and includes advanced evasion techniques such as Windows Defender destruction sequences and payload hash rotation, complicating detection and remediation efforts.

Defensive Guidance

No official patch or fix is applicable as this campaign abuses legitimate software and social engineering techniques. Organizations should be aware of this campaign and focus on detecting abnormal use of ScreenConnect RMM agents and monitoring for suspicious network connections to unknown relay servers. Security teams should verify the legitimacy of ScreenConnect installations and consider restricting or monitoring the use of remote management tools. Since the payloads are signed, reliance solely on code signing for trust should be reconsidered. Vendor advisories or updates specific to this campaign were not provided; therefore, patch status is not confirmed—check vendor advisories for any updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels"]
Adversary
null
Pulse Id
6a722d8bdafe1dfae681f87b
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip142.202.191.225
ip207.174.0.143
ip207.189.11.170

Hash

ValueDescriptionCopy
hash9161a8f7f07741db06b9f9a87b6ec7f277faf2ae3a3a661d6eb09cec4e12b920
hashdc8b056dd6eb75df21e9721ac2e340f91bb5e94d5a6ff412d7d0c7539e0f06e2
hash433b61c29aefaa5b55fe78063e6ad8597d3835f36e1242d5402ab23e6dc61194
hash8e87a734daddd95322b3f18f71eb9275219e244aac4f62b8dc6da6e2e91525e9
hash3cd9b7d583442963261f9985128042bf45d25482efcbf903c9248837cb0d744b
hashdd23012b4dc29cf7901185ae4fb2d507e737e9ea4d467846eafd6a86b26486bf
hashaa84e2ac68f7fc18f4927b89be7b4a7739f2eaf099e489aa0f65c1d3913ce62a
hash3d4d54fb1aaa70005f040558b5d4cd0c
hash5731b2f26146fe379f27bbfc5608f4e9ab11a9d3
hash01e4cb3c60fa50b2927daa11f25a3c412549680406fc121a3d1870a9a33f5d38
hash9d9f3fa5aaf6bc91091873bd7ee04f0cc23e8709e4ad20c61d2779ff1a43c4b4
hash04ec5209d922b98a947fea48c73ecaa8
hash2f1e4fd2937ccf825a555204b1741f89
hash37da3d949d76c4867c6e8812f2c38f94
hash3cbf062f600bb6c64849f726566557bc
hash57d20ed65870aa249ca374142d763d13
hash690401ed2497ad939e05e0bddfd13dbe
hash73167f265dfbd888e514a3730228d82f
hash86db42b1595d14e0f5bd9816e42423cc
hashb09c029c6f88a6dad8ef690f9c42f2a5
hashb62119f0ae9ad41612f252dd703799d4
hashe9174663dd353d0faf56f005cf30a652
hashf2d291955c241b3967e636c03cf28c7e
hash19e06d1bf248d1b1ad0d4a1fca8b4dde4733ca43
hash2c32f560af970493724544b19b05363db6e36d25
hash2d8faea3e5170802ff2212f862fd5ef1528289ae
hash4e3422e4848147d648c5e82dfeb163035a10bf26
hash7618dd88cf6a07df1c64ce71dabc1a8167aefcc6
hash897a9a38ebc67beb0775184520c8ce3b0bec04e5
hash923a3c6a7006d0e0fde4deadec5a9cd0b075d122
hasha54e21752a34a4663cef87b75efe74be139a2c8e
hasha83a5e93cfb4d1fd65054017abfb7827b48f2e5a
hashe30f1c194b0c850eb79b4bc39084c75b6aea423b
hashea37f1e3004a5c20af5802c35eb2275594db9c59
hashf67016820b113661570f3cee5c070d84bc1b534d
hash2423decbfcf820f41bc356547e4e18e61d60c9829421d7121c374dcef88577f7
hash31260c37cc442719ac84540f4159dd9d4738575d2ab05e92c751a9b4b5f9b91b
hash35be1b070f06eb313c3cb818c74aa0a9c2d9f39a05621dac4de6cff6067a5d12
hash371166ebd83e8318b49ba71321396524fbca7dc42fe1ca4badda8af794bf5a59
hash5253e66f1f493c4e13539749f1aa86fd0c61e3072900fec29a44ba046a6d97e2
hash60c730addd2a15e4213a1d37f55186686976de73a106317b5a258fe0121cfd5c
hash639430a33c0ecdf5a134501788a3a40f065ae4232efc66e1b82eca2b355e0606
hash63c46b3c090a4b1efef146f2f1efc4f93d44f21db21d7825f43e02c3c5c89de6
hash873011c181d00709fdf66f32bb3cca0c5ff3147d00ef818fef72987a6773ea66
hashaefac65c42c0c72ed3e08b32774fa1b902f4fd1d53de189d50f38130cc357764
hashc8695906dcefc64becb3123fa0a8058278c8c2f9c86130956b6b10d49c1a35dc

Url

ValueDescriptionCopy
urlhttp://207.189.11.170/Bin/working_payload.cs

Domain

ValueDescriptionCopy
domaincrestmarkhq.com
domainblog.derrspecial-onlinedmin.live
domainsubscription-magnetic-recommended-meat.trycloudflare.com
domainderrspecial-onlinedmin.live

Threat ID: 6a7301c5bf8831d539a3dd23

Added to database: 08/05/2026, 09:26:29 UTC

Last enriched: 08/05/2026, 11:28:32 UTC

Last updated: 08/05/2026, 19:32:31 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses