#ScreenConnect
Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client's  Authenticode signature.
Hackers turn ScreenConnect into malware using Authenticode stuffing
Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client's  Authenticode signature.
www.bleepingcomputer.com
June 25, 2025 at 9:52 PM
Fake desktop app pages for US payroll and HR platforms lured users into installing ScreenConnect, giving attackers hidden remote access and a path to divert paychecks. #PayrollFraud #ScreenConnect #US
Fake Payroll Desktop Apps Hand Attackers A Route To Company Paychecks
An attacker created fake desktop app pages for three major US payroll and HR platforms that do not offer desktop apps, then used them to install ScreenConnect for hidden remote access. The campaign used AI-generated lure pages, GitHub-hosted installers, and a single command-and-control server to potentially divert or drain payroll accounts. #ScreenConnect #Lovable #Vercel #GitHub
www.hendryadrian.com
September 25, 2026 at 11:00 AM
Hackers Deploy AsyncRAT and SectopRAT Using ScreenConnect Software on Windows
Hackers Deploy AsyncRAT and SectopRAT Using ScreenConnect Software on Windows
Cybercriminal groups are increasingly blending new and traditional techniques to steal sensitive information from unsuspecting users by deploying remote access tools (RATs) such as AsyncRAT and SectopRAT.
cybersecuritynews.com
December 24, 2024 at 5:30 AM
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
www.bleepingcomputer.com
September 16, 2026 at 11:18 AM
The Weekly Bulletin is live. Highlights include SEO poisoning spoofing the NJMVC portal to steal payment data, Calendly phishing lures dropping ScreenConnect software, and more!

Read: https://www.cyber.nj.gov/threat-landscape/weekly-bulletin
September 25, 2026 at 6:01 PM
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.
www.bleepingcomputer.com
September 7, 2026 at 10:06 AM
Now that the cat is out of the bag:
Write-up on how ConnectWise misused Microsoft Authenticode signatures, creating the ideal platform for threat actors to modify ScreenConnect installers into initial payloads (previously disclosed to vendor & DigiCert)

blog.randomoracle.io/2025/06/26/s...
ScreenConnect: “unauthenticated attributes” are not authenticated
(Lessons from the ScreenConnect certificate-revocation episode) An earlier blog post recounted the discovery of threat actors leveraging the ScreenConnect remote assistance application in the wild,…
blog.randomoracle.io
June 26, 2025 at 4:04 PM
Yeah, I just saw ScreenConnect Client listed under services and I’m going to melt this fucking thing down to slag
August 28, 2025 at 1:35 AM
A new backdoor malware that uses the legitimate remote access software ScreenConnect was discovered in a malicious email campaign, raising cybersecurity concerns. #ScreenConnect #malware #cybersecurity https://malware.news/t/2026-09-14-backdoor-using-screenconnect-from-malicious-emailt/125740
2026-09-14: Backdoor using ScreenConnect from malicious emailt - Malware Analysis - Malware Analysis, News and Indicators
Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coupon Code MWNEWS10 Note: Affiliate link – your en…
malware.news
September 22, 2026 at 3:23 AM
A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it's come to Mac.
Fake Zoom update malware campaign expands its reach to macOS
A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it's come to Mac.
appleinsider.com
August 4, 2026 at 1:27 PM
ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation.
ConnectWise patches new flaw allowing ScreenConnect hijacking
ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation.
www.bleepingcomputer.com
March 18, 2026 at 6:10 PM
Gruselige Details: der eingeschleuste Ordner hieß Microsoft MV, der Prozess nannte sich Microsoft. Genutzt wurde eine kompromittierte ScreenConnect Installation.

2/2
March 31, 2026 at 2:04 PM
IT management software firm ConnectWise says a suspected state-sponsored cyberattack breached its environment and impacted a limited number of ScreenConnect customers.
ConnectWise breached in cyberattack linked to nation-state hackers
IT management software firm ConnectWise says a suspected state-sponsored cyberattack breached its environment and impacted a limited number of ScreenConnect customers.
www.bleepingcomputer.com
May 29, 2025 at 7:12 PM
Derzeit läuft eine Phishing-Kampagne, die Zugangsdaten zu ScreenConnect abgreift. Die Angreifer wollen Ransomware platzieren. #Security
ScreenConnect-Admins im Visier von Spear-Phishing-Angriffen
Derzeit läuft eine Phishing-Kampagne, die Zugangsdaten zu ScreenConnect abgreift. Die Angreifer wollen Ransomware platzieren.
www.heise.de
August 26, 2025 at 7:53 AM
2026-09-14: Backdoor using ScreenConnect from malicious emailt

huntaegis.com
September 23, 2026 at 7:26 PM
Microsoft finds a team within Sandworm has been carrying out widespread initial access operations on behalf of the GRU group and focused on US, UK, Canada and Australia networks over 2024, exploiting Connectwise ScreenConnect and Fortinet FortiClient EMS. www.wired.com/story/russia...
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 12, 2025 at 5:07 PM
Looking at the code, the ENTIRE extension is malicious code. It runs a remote powershell script which installs ScreenConnect RMM giving access to your system the moment the extension is installed.
August 12, 2025 at 5:08 PM

#NorthKorean hackers exploit ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708 & CVE-2024-1709) to deploy TODDLERSHARK malware, adding to the notorious Kimsuky arsenal alongside BabyShark and ReconShark. #malware
thehackernews.com/2024/03/hack...
Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware
North Korean hackers exploit ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708 & CVE-2024-1709) to deploy TODDLERSHARK malware.
thehackernews.com
March 6, 2024 at 8:37 PM
Cursor is now using Open VSX to install code editor extensions from. You must understand the implications of this!

There has been an attack campaign happening for more than a month with extensions that install ScreenConnect.
August 12, 2025 at 5:08 PM
ハッカー、ネットワーク侵入にScreenConnect機能標的
#CybersecurityNews
www.infosecurity-magazine.com/news/hackers...
Hackers Target ScreenConnect Features For Network Intrusions
A rise in attacks exploiting RMM tools like ScreenConnect enables system control via phishing tactics
www.infosecurity-magazine.com
October 13, 2025 at 6:26 PM
🚨 ScreenConnect admins under siege

Since 2022, stealthy spear-phishing campaigns target #ScreenConnect super-admins via compromised Amazon SES emails and EvilGinx proxy pages.

Stolen credentials enable lateral movement and #ransomware deployment.

#ransomNews #CredentialHarvest #RMMThreat
August 28, 2025 at 7:37 PM
ConnectWise is warning customers that it is rotating the digital code signing certificates used to sign ScreenConnect, ConnectWise Automate, and ConnectWise RMM executables over security concerns.
ConnectWise rotating code signing certificates over security concerns
ConnectWise is warning customers that it is rotating the digital code signing certificates used to sign ScreenConnect, ConnectWise Automate, and ConnectWise RMM executables over security concerns.
www.bleepingcomputer.com
June 10, 2025 at 9:18 PM
www.pcmag.com/news/beware-...
Beware this malware posing as Social Security info. You could lose everything.
#CyberSec #MalWare #RAT
Beware: This Social Security Scam Installs Remote Access Malware on Your PC
The emails prompt you to download a Social Security statement, but clicking will allow malicious actors to install a remote access tool called ScreenConnect.
www.pcmag.com
May 8, 2025 at 7:59 PM