Threat Advisory

Phishing Campaign Misuses ScreenConnect Tool as Payment Documents for External Access

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A phishing campaign is abusing the legitimate ScreenConnect remote access client to gain potential remote access to targeted systems. The campaign uses a fraudulent payment notification and invoice-themed message to convince recipients to view an expected PDF document. Instead of a document the provided link delivers a Windows executable containing a genuine ScreenConnect installer configured to connect to an attacker-controlled ScreenConnect cloud instance. The activity demonstrates how legitimate remote management software can be misused as the access mechanism without requiring a modified or malicious binary.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A phishing campaign is abusing the legitimate ScreenConnect remote access client to gain potential remote access to targeted systems. The campaign uses a fraudulent payment notification and invoice-themed message to convince recipients to view an expected PDF document. Instead of a document the provided link delivers a Windows executable containing a genuine ScreenConnect installer configured to connect to an attacker-controlled ScreenConnect cloud instance. The activity demonstrates how legitimate remote management software can be misused as the access mechanism without requiring a modified or malicious binary.[emaillocker id="1283"]

The phishing email claims that a payment has been received and directs the recipient to review order information through a PDF-themed link. The link instead downloads ScreenConnect.ClientSetup.exe. Analysis of the executable identified a valid ConnectWise digital signature with an Authenticode digest matching the signed content and no evidence of appended data, certificate modification or binary tampering. The client was preconfigured to communicate over port 443 with a cloud-hosted ScreenConnect relay, directing connections toward a specific ScreenConnect instance rather than an approved organizational support environment.

The campaign highlights the challenge of detecting abuse of legitimate remote management software because the delivered executable is authentic and digitally signed rather than modified malware. Organizations should scrutinize unexpected ScreenConnect installations originating from financial or document-themed phishing messages and correlate email delivery context with process execution and subsequent remote connections. Monitoring for unauthorized ScreenConnect instances and investigating unexpected remote management sessions can help identify attempts to establish unauthorized remote access.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Command and control T1071.001 Application Layer Protocol Web Protocols

 

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/screenconnect-tool/

[/emaillocker]
crossmenu