Overview
- Researchers traced the campaign to a live WsgiDAV staging server and published findings on Tuesday that show social-engineered lures install ScreenConnect clients configured to contact three separate attacker-controlled relay clusters.
- Attackers deliver payloads with polished fake Zoom or Adobe update pages, business-document and maintenance-themed files, Dropbox links and Cloudflare Quick Tunnel endpoints to trick users into running installers.
- The final payloads are genuine ConnectWise ScreenConnect installers signed with a DigiCert chain that are reconfigured to beacon to attacker relays, giving operators persistent remote desktop and management access that looks like normal IT activity.
- Early Windows loaders tried to weaken Microsoft Defender and SmartScreen and add Defender exclusions but later samples removed that behavior and introduced multi-minute delays and encrypted bundles to avoid endpoint-detection correlation.
- Securonix urges defenders to inventory approved RMM tools, block or flag ScreenConnect agents that connect to raw IPs, restrict untrusted MSI execution, monitor for security-process tampering and inspect how any ScreenConnect install was launched.