Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'screenconnect'

View all threats tagged with 'screenconnect'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: screenconnect

Threats Tagged 'screenconnect'

Click on any threat for detailed analysis and mitigation recommendations

ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
0

Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

Join the discussion
Phishing Email Delivers ScreenConnect Malware
0

A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.

Join the discussion
From E-Sign to RMM: DocuSign Kit Targets Windows and...
0

A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

Join the discussion
CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce RansomwareCVE-2017-18362
0

Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances. Attackers sent malformed pre-authentication login requests that leaked NetScaler memory containing valid session tokens, bypassing multi-factor authentication by hijacking active sessions. Following initial access, threat actors consistently escalated privileges to SYSTEM using a registry-symlink exploitation technique targeting the AppMgmt service, created rogue administrator accounts (CtxAppVCOMService, ctxsvc, test), and established persistence through legitimate remote access tools including ScreenConnect and Zoho Assist. The most advanced case culminated in DragonForce ransomware deployment. The highly standardized tradecraft, reused infrastructure, and consistent indicators across unrelated victims suggest a single Initial Ac...

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: screenconnect
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses