Skip to main content

Threats Tagged 'screenconnect'

View all threats tagged with 'screenconnect'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: screenconnect

Threats Tagged 'screenconnect'

Click on any threat for detailed analysis and mitigation recommendations

Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

Join the discussion

Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...

Join the discussion

Multiple organizations experienced attacks beginning with social engineering that led to rogue ScreenConnect installations executing suspicious VBScript files. The attack chain involved four sequential VBScript payloads (1.vbs through 4.vbs) used to profile systems, check for security products, establish persistence, and deploy additional tools. Modified ScreenConnect clients enabled worm-like propagation by automatically transferring and executing these scripts on newly connected endpoints. The attacks included deployment of additional RMM tools like UltraViewer, cryptocurrency miners, and tunneling utilities. Systems were profiled based on installed security products, RAM capacity, and existing ScreenConnect installations. Persistence was achieved through Windows Registry Run Keys and concealed services. The campaign demonstrated sophisticated evasion techniques including AMSI bypass attempts, Windows Defender exclusions, and UAC bypass mechanisms.

Join the discussion

A sophisticated phishing campaign has been identified where attackers impersonate employees of a US company, sending emails that claim to contain transaction receipts. Recipients are urged to verify fund deposits by opening an attached PDF file. The malicious PDF displays a fake Adobe Flash Player update prompt, which when clicked, downloads a VBS script. This script executes with administrator privileges, displays a decoy payment receipt document, and silently installs ScreenConnect remote management software via an MSI package. The installation establishes persistent remote access to the compromised system, enabling attackers to execute commands, transfer files, and deploy additional payloads using legitimate administrative tools in a Living-off-the-Land attack technique.

Join the discussion

Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

Join the discussion

A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.

Join the discussion

A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

Join the discussion

Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances. Attackers sent malformed pre-authentication login requests that leaked NetScaler memory containing valid session tokens, bypassing multi-factor authentication by hijacking active sessions. Following initial access, threat actors consistently escalated privileges to SYSTEM using a registry-symlink exploitation technique targeting the AppMgmt service, created rogue administrator accounts (CtxAppVCOMService, ctxsvc, test), and established persistence through legitimate remote access tools including ScreenConnect and Zoho Assist. The most advanced case culminated in DragonForce ransomware deployment. The highly standardized tradecraft, reused infrastructure, and consistent indicators across unrelated victims suggest a single Initial Ac...

Join the discussion

A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support.

Join the discussion

ScreenConnect is used in phishing URLs to deliver RMM payload. DocuSign has been observed to be the common theme in these phishing emails.

Join the discussion

Showing 1 to 10 of 30 results

Filters:Tag: screenconnect
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses