ScreenConnect, also known as ConnectWise Control, is a legitimate commercial remote monitoring and remote administration tool that is widely used by IT administrators but is heavily abused by threat actors as a malware-enabling access component. Across the provided reporting, attackers use ScreenConnect to obtain persistent unattended remote access, transfer files, execute commands, deploy follow-on payloads, and maintain redundant access alongside other RMM tools. It is frequently delivered as a second-stage payload after initial compromise, but is also used directly for initial access via phishing, fake software installers, malicious extensions, and exploitation chains.
Observed infection vectors include SEO-poisoned and spoofed software download sites, phishing campaigns, trojanized installers, malicious VBS and PowerShell droppers, DLL sideloading chains, abuse of legitimate ConnectWise cloud provisioning, and attempted deployment following exploitation of server-side vulnerabilities. Multiple campaigns disguised ScreenConnect as legitimate Windows software such as OBS Studio, DNS Jumper, DS4Windows, Bandicam, VLC Media Player, CrystalDiskInfo, HWMonitor, FurMark, K-Lite Codec Pack, PDFgear, and other utilities. In several cases, attackers bundled legitimate signed binaries with malicious DLLs such as install.res.1033.dll, libvlc.dll, or autorun.dll to silently install ScreenConnect via msiexec.exe without requiring a reboot.
Threat actors and clusters explicitly associated in the content include unknown operators in large SEO-poisoning campaigns, The Quarry phishing-as-a-service ecosystem, MERCURY/Mango Sandstorm, Storm-2949, Interlock ransomware operators, and multiple unrelated cybercrime actors abusing ConnectWise trial or self-hosted infrastructure. ScreenConnect was used to deploy or support follow-on malware including AsyncRAT, Quasar, PureLogs-detected stealer activity, cryptocurrency miners including gminer, lolMiner, and SRBMiner-MULTI, and custom implants. In some intrusions it was paired with Syncro, JumpCloud, GetScreen, SuperOps, Atera, PDQ Connect, or other RMM tools for layered persistence.
Behavior described in the content includes installation as a Windows service, often under deceptive names such as Microsoft Update Service; registration of persistence-related components including scheduled tasks, SafeBoot entries, Windows Authentication Package loading, Credential Provider registration, and custom URL protocol handlers; and communication with attacker-controlled relay or panel infrastructure. Reported infrastructure and indicators include relay.lmfao[.]su, r.servermanagemen[.]xyz, mora1987.work[.]gd as related follow-on C2 in AsyncRAT chains, 193.42.11[.]108, 185.241.208[.]243:9090, 80.76.49[.]161:8040/8041, instance-y9tbyl-relay.screenconnect[.]com, and multiple other screenconnect[.]com relay instances. Additional observed artifacts include the service name Microsoft Update Service, scheduled task MasterPackager.Updater, and installer URLs such as /Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest.
Targeting in the provided content spans individual users, enterprise environments, taxpayers, blockchain developers, gamers, hardware enthusiasts, AI developers, and organizations in sectors including education, engineering, construction, manufacturing, healthcare, government, and the public sector. The main security significance is that ScreenConnect itself is legitimate and signed, which helps attackers evade reputation- and signature-based defenses while preserving durable remote access for credential theft, data theft, lateral movement, ransomware staging, cryptomining, and broader post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixed version, version 7.4.4, as soon as possible. CVE-2025-47812 is a null byte and Lua injection flaw that can lead to root/SYSTEM-level remote code execution if exploited.
First observed in February 2026, the STAC3725 campaign exploits the CitrixBleed2 vulnerability (CVE-2025-5777) to gain access and then installs a malicious ScreenConnect client to maintain persistence.
...Fortinet FortiClient EMS... exploited... The vulnerability in question is CVE-2023-48788... SQL injection...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation uses legitimate RMM software (primarily ConnectWise ScreenConnect) as its final payload, giving operators remote access to victim machines while avoiding the detection signatures associated with traditional malware.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
MERCURY operators include links to or directly attach commercial remote access tools, such as ScreenConnect, in these initial phishing mails.
The operator establishes endpoint persistence via two legitimately-signed RMMs deployed in parallel: ConnectWise ScreenConnect from attacker infrastructure at 185.241.208[.]243:9090 ... MALWARE ScreenConnect / ConnectWise (legitimate build abused via deployment vector), Evilconwi (Malpedia family alias for the Storm-2949 ScreenConnect variant)
In 2024, Proofpoint researchers observed a notable increase in the use of RMM tools from cybercriminal threat actors in documented campaigns, including using payloads such as ScreenConnect, Fleetdeck, and Atera.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.
Once installed, the tools provide attackers with persistent remote access to compromised systems.
Threat actors leverage SEO techniques to push these fraudulent websites to the top of search engine results.
CyberProof researchers identified ConnectWise ScreenConnect binaries with valid digital signatures making outbound connections to suspicious command-and-control (C2) servers. This attack involved Authenticode Stuffing—injecting malicious code while preserving the integrity of the original signature.
Persistence is maintained through a scheduled task that runs every two minutes, ensuring the attack chain restarts after a reboot.
The service creates and executes a PowerShell script ... and then creates a Visual Basic Script (VBScript) file ... In the next stage, it triggers the execution of 'script.vbs'...
сервис Kaspersky Managed Detection and Response зафиксировал подозрительные PowerShell- и VBS-скрипты, запущенные процессом ScreenConnect.
сервис Kaspersky Managed Detection and Response зафиксировал подозрительные PowerShell- и VBS-скрипты, запущенные процессом ScreenConnect.
The threat actor lured a victim to download a backup software; the software created a new firewall rule to allow the installation of two ScreenConnect instances and RMM Agent on the host.
Persistence is maintained through a scheduled task that runs every two minutes, ensuring the attack chain restarts after a reboot.
Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.
Persistence is maintained through a scheduled task that runs every two minutes, ensuring the attack chain restarts after a reboot.
Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.
2026-05-19 11:57:58 Run-key persistence added: PayloadService → payload.exe.
операторы которой распространяют легитимный инструмент удаленного доступа ScreenConnect, маскируя его под популярные программы для Windows. Вредоносные сайты имитируют официальные страницы OBS Studio, DNS Jumper, DS4Windows, Glary Utilities, Bandicam, Process Hacker и других бесплатных утилит.
Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.
ConnectWise ScreenConnect binaries with valid digital signatures making outbound connections to suspicious command-and-control (C2) servers.
365 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote access tool abused as the initial access and persistence mechanism in the campaign. It is silently installed via DLL sideloading, registered as a service under a benign name, and used to connect the victim system to attacker-controlled infrastructure before deploying AsyncRAT.
Legitimate remote access software abused in this campaign as an intermediary payload and persistence/control mechanism to deploy and execute AsyncRAT on victim systems.
Legitimate remote management tool abused as the primary delivery and persistence mechanism in the campaign; installed covertly via fake software sites and used to execute scripts, disable defenses, and deploy AsyncRAT.
ScreenConnect is a legitimate remote management utility abused in this campaign as the initial remote access component. It is silently installed via DLL sideloading and MSI execution, creates a service for attacker-controlled access, launches malicious scripts, and facilitates delivery of the AsyncRAT payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.