ConnectWise ScreenConnect, also known as ConnectWise Control, is a legitimate, code-signed remote monitoring and management tool that has been extensively abused as an unauthorized remote-access implant on Windows systems. Malicious deployments register endpoints to attacker-controlled ScreenConnect instances, giving operators interactive control, file transfer, remote command execution, and durable unattended access while blending with legitimate IT administration activity. It is frequently used as a second-stage access tool after phishing, social engineering, remote-support scams, compromised RMM products, or trojanized software downloads.
Observed abuse includes phishing pages impersonating document-sharing, government, meeting, software-update, and business services; SEO-poisoned software-download sites; malicious installers delivered through DLL sideloading; and chained RMM deployments. Attackers commonly silently install ScreenConnect alongside a decoy application or document, configure it as a disguised or concealed service, and use it to deploy scripts and follow-on malware. Campaigns have used ScreenConnect to establish persistence, execute hands-on-keyboard activity, distribute scripts to connected endpoints, weaken endpoint protections, bypass UAC, and deploy payloads including AsyncRAT, XLoader/FormBook, Quasar, cryptocurrency miners, and tunneling utilities.
Modified ScreenConnect clients have also been observed propagating staged scripts to newly connected hosts through the product's virtual file-transfer and execution functionality, enabling worm-like spread between managed endpoints. Financially motivated operators, phishing-as-a-service affiliates, access brokers, cryptojacking operators, and ransomware-adjacent intrusions have all abused ScreenConnect. Affected targets include individual users, enterprises, government organizations, transportation and logistics entities, and high-performance Windows workstations targeted for GPU cryptomining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Beginning on March 24th, 2024, eSentire observed a significant increase in exploitation of CVE-2023-48788 (CVSS: 9.8). CVE-2023-48788 is a SQL injection flaw in FortiClientEMS software. Exploitation would allow an unauthenticated remote threat actor to execute code or commands through specially crafted requests, enabling initial access into organizations.
The TrendAI Vision One MDR team has been observing the recurring abuse of ConnectWise ScreenConnect, a legitimate and code-signed remote-support (RMM) tool. This involves using ScreenConnect as a covert remote-access tool (RAT) spanning different intrusions, different victims, and separate infrastructure.
The TrendAI Vision One MDR team has been observing the recurring abuse of ConnectWise ScreenConnect, a legitimate and code-signed remote-support (RMM) tool. This involves using ScreenConnect as a covert remote-access tool (RAT) spanning different intrusions, different victims, and separate infrastructure.
CVE-2025-47812 (CVSS skóre 10,0) Kritická zraniteľnosť sa nachádza vo webovom rozhraní servera a spočíva v nesprávnom spracovaní tzv. nulových bajtov ('\0') v rámci parametra username v koncovom bode loginok.html. Vzdialený neautentifikovaný útočník by ju mohol zneužiť na injekciu kódu v jazyku Lua do súborov používateľských relácií a následné vykonanie systémových príkazov s oprávneniami root (Linux) alebo NT AUTHORITY\SYSTEM (Windows).
First observed in February 2026, the STAC3725 campaign exploits the CitrixBleed2 vulnerability (CVE-2025-5777) to gain access and then installs a malicious ScreenConnect client to maintain persistence.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation uses legitimate RMM software (primarily ConnectWise ScreenConnect) as its final payload, giving operators remote access to victim machines while avoiding the detection signatures associated with traditional malware.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
MERCURY operators include links to or directly attach commercial remote access tools, such as ScreenConnect, in these initial phishing mails.
The operator establishes endpoint persistence via two legitimately-signed RMMs deployed in parallel: ConnectWise ScreenConnect from attacker infrastructure at 185.241.208[.]243:9090 ... MALWARE ScreenConnect / ConnectWise (legitimate build abused via deployment vector), Evilconwi (Malpedia family alias for the Storm-2949 ScreenConnect variant)
In 2024, Proofpoint researchers observed a notable increase in the use of RMM tools from cybercriminal threat actors in documented campaigns, including using payloads such as ScreenConnect, Fleetdeck, and Atera.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Напаѓачот ја користи функционалноста на Faronics за далечинско распоредување софтвер за да извршува PowerShell скрипти на приклучениот компјутер без дополнителна интеракција од страна на корисникот.
Le client ScreenConnect malveillant exécute wscript.exe de manière répétée pour lancer quatre fichiers VBScript (1.vbs, 2.vbs, 3.vbs, 4.vbs).
Le contenu identifie T1543.003 parmi les TTPs et répertorie ScreenConnect.ClientService.exe.
Later scripts pull down and decrypt additional payloads.
“After a 5-second nap, the script deletes A.msi and then removes itself” using “cmd /c ping 127.0.0.1 -n 3 >nul && del /f /q”.
639 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
64 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Des clients ScreenConnect modifiés et malveillants servent de RAT/backdoor et de mécanisme de propagation vermiforme. Ils exécutent une chaîne VBScript en quatre étapes, profilent les hôtes, récupèrent des payloads conditionnels et établissent une persistance via une clé Run HKCU.
Trojanized remote-management clients used for persistent remote access and worm-like propagation. The modified client detects newly connected ScreenConnect Host sessions and causes them to receive and execute a four-stage VBScript payload chain.
Legitimate remote-monitoring-and-management software abused as persistent remote access infrastructure. In this intrusion it provided redundant interactive control and was used to execute post-compromise tooling, including credential-access and collection utilities.
Described here as a traffic distribution system using compromised WordPress sites to deploy malicious code that can lead to malware delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.