Threats Tagged 'screenconnect deployment'
View all threats tagged with 'screenconnect deployment'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'screenconnect deployment'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated web campaign was blocked that used fake DocuSign workflows and deceptive cloud infrastructure to socially engineer victims into downloading malicious files. The attack employed a ZIP archive with a malicious HTA file using encoded VBScript, fake Adobe interfaces, privilege escalation, and registry modifications to bypass security. It leveraged native Windows tools to silently install ConnectWise ScreenConnect clients, enabling unauthorized remote access. The campaign was stopped at the web entry point before any payload delivery occurred. Join the discussion | AlienVault OTX General | 09/11/2026, 03:23:51 UTC Added: 09/11/2026, 14:47:25 UTC |
Showing 1 to 1 of 1 result