ConnectWise ScreenConnect, also known as ConnectWise Control, is a legitimate, code-signed remote monitoring and management product that has been repeatedly abused as an unauthorized remote-access implant on Windows systems. Attacker-configured clients register to adversary-controlled ScreenConnect instances, enabling unattended interactive control, remote terminal access, file transfer, execution of scripts and binaries, and durable service-based access. Its legitimate signing, administrative functionality, and frequent enterprise allowlisting can allow malicious deployments to blend with authorized IT activity.
Abuse has been documented across financially motivated intrusion sets, phishing-as-a-service operations including The Quarry, malware-distribution campaigns, and cryptojacking activity. Common infection chains use phishing and fake document, meeting, invitation, or software-update lures; spoofed software-download sites promoted through SEO poisoning; and trojanized installers. Some campaigns use DLL sideloading to silently install both the expected application and ScreenConnect. Other intrusions deploy it after an initial foothold through another RMM tool, Quick Assist, a malicious browser or developer-tool extension, or exploitation of an internet-facing service.
Malicious ScreenConnect deployments commonly establish persistent unattended access and are used for hands-on-keyboard post-exploitation. Operators have used the tool to transfer and run PowerShell, VBScript, and other payloads; install additional RMM tools, RATs, credential stealers, and cryptocurrency miners; alter endpoint protections; and remove competing remote-access software. Modified clients have also abused ScreenConnect file-transfer and execution features to propagate staged scripts to newly connected hosts, producing worm-like lateral spread. ScreenConnect itself is legitimate software; maliciousness depends on the authorization, installer origin, relay configuration, and operator activity associated with a deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Beginning on March 24th, 2024, eSentire observed a significant increase in exploitation of CVE-2023-48788 (CVSS: 9.8). CVE-2023-48788 is a SQL injection flaw in FortiClientEMS software. Exploitation would allow an unauthenticated remote threat actor to execute code or commands through specially crafted requests, enabling initial access into organizations.
The TrendAI Vision One MDR team has been observing the recurring abuse of ConnectWise ScreenConnect, a legitimate and code-signed remote-support (RMM) tool. This involves using ScreenConnect as a covert remote-access tool (RAT) spanning different intrusions, different victims, and separate infrastructure.
The TrendAI Vision One MDR team has been observing the recurring abuse of ConnectWise ScreenConnect, a legitimate and code-signed remote-support (RMM) tool. This involves using ScreenConnect as a covert remote-access tool (RAT) spanning different intrusions, different victims, and separate infrastructure.
CVE-2025-47812 (CVSS skóre 10,0) Kritická zraniteľnosť sa nachádza vo webovom rozhraní servera a spočíva v nesprávnom spracovaní tzv. nulových bajtov ('\0') v rámci parametra username v koncovom bode loginok.html. Vzdialený neautentifikovaný útočník by ju mohol zneužiť na injekciu kódu v jazyku Lua do súborov používateľských relácií a následné vykonanie systémových príkazov s oprávneniami root (Linux) alebo NT AUTHORITY\SYSTEM (Windows).
First observed in February 2026, the STAC3725 campaign exploits the CitrixBleed2 vulnerability (CVE-2025-5777) to gain access and then installs a malicious ScreenConnect client to maintain persistence.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operation uses legitimate RMM software (primarily ConnectWise ScreenConnect) as its final payload, giving operators remote access to victim machines while avoiding the detection signatures associated with traditional malware.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
Beyond the financial motive of cryptocurrency mining, the attackers also install ScreenConnect on compromised machines to maintain persistent remote access.
MERCURY operators include links to or directly attach commercial remote access tools, such as ScreenConnect, in these initial phishing mails.
The operator establishes endpoint persistence via two legitimately-signed RMMs deployed in parallel: ConnectWise ScreenConnect from attacker infrastructure at 185.241.208[.]243:9090 ... MALWARE ScreenConnect / ConnectWise (legitimate build abused via deployment vector), Evilconwi (Malpedia family alias for the Storm-2949 ScreenConnect variant)
In 2024, Proofpoint researchers observed a notable increase in the use of RMM tools from cybercriminal threat actors in documented campaigns, including using payloads such as ScreenConnect, Fleetdeck, and Atera.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Напаѓачот ја користи функционалноста на Faronics за далечинско распоредување софтвер за да извршува PowerShell скрипти на приклучениот компјутер без дополнителна интеракција од страна на корисникот.
Each infected machine began repeatedly launching the Windows Script Host process to run a sequence of four VBScript files, named simply 1.vbs through 4.vbs.
Later scripts pull down and decrypt additional payloads.
The payload is presented through “secure e-vite” and “IRS transcript viewer” themes, while the downloaded installer is staged as “C:\Windows\Temp\A.msi.”
“After a 5-second nap, the script deletes A.msi and then removes itself” using “cmd /c ping 127.0.0.1 -n 3 >nul && del /f /q”.
639 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojanized remote-management clients used for persistent remote access and worm-like propagation. The modified client detects newly connected ScreenConnect Host sessions and causes them to receive and execute a four-stage VBScript payload chain.
Legitimate remote-monitoring-and-management software abused as persistent remote access infrastructure. In this intrusion it provided redundant interactive control and was used to execute post-compromise tooling, including credential-access and collection utilities.
Described here as a traffic distribution system using compromised WordPress sites to deploy malicious code that can lead to malware delivery.
A legitimate remote-support/RMM tool abused as a covert remote-access implant. Attackers deliver attacker-configured, code-signed ScreenConnect clients via phishing, SEO poisoning, malvertising, and RMM chaining, then use them for persistent remote control, command execution, service-based persistence, credential-provider registration, and hands-on-keyboard activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.