ConnectWise Control (formerly ScreenConnect) is a legitimate remote access and remote monitoring tool that has been observed abused in malicious operations. In the provided reporting, a trojanized payload named WinDesk.Client.exe was delivered through brand-impersonation phishing and subscription-cancellation scam infrastructure spoofing organizations such as PayPal, Amazon, Microsoft, Geek Squad, and Norton. After execution, the observed process chain involved dfsvc.exe launching ScreenConnect.WindowsClient.exe and screenconnect.clientservice.exe. The final dropped service attempted to connect to 104.168.5[.]29, which resolved to firsto[.]cc. The activity was associated with a broader phishing ecosystem including domains such as paypalsec[.]us, help01[.]us, firsto[.]top, firsto[.]cc, mslxt[.]xyz, ncareback[.]xyz, backup02[.]xyz, gkscare[.]com, geeksupportcare[.]com, xpchelps[.]us, support2norton[.]us, and xpchelp[.]us, as well as payload download domains win01[.]xyz through win04[.]xyz. The likely infection vector in that reporting was email-based social engineering followed by phone interaction to convince victims to enter a code and download the payload. Separately, the content states that Scattered Spider members deploy commercial RMM software including ConnectWise Control, along with AnyDesk and LogMeIn, to establish persistence on compromised networks. High-confidence indicators directly tied to the observed ConnectWise Control abuse include ScreenConnect.WindowsClient.exe, screenconnect.clientservice.exe, 104.168.5[.]29, and firsto[.]cc.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
authorities warn the same tactics could be used by APT actors in order to gain persistence within a network.
Initial access was varied: Social engineering using phone calls and text messages to impersonate IT personnel, and either directing victims to a credential harvesting site or directing victims to run commercial Remote Monitoring and Management (RMM) tools.
Via the ConnectWise Control center it's possible to type a command, hit the 'Run Command' button, after which the command is executed. The commands that are allowed to be used are the commands that are generally supported by the Windows Command Prompt.
However, manually-executed shell commands are launched from ScreenConnect.ClientService.exe as command (.cmd) scripts, whereas tasks like process listing and termination are executed via Powershell (.ps1) scripts.
ConnectWise Control (among others) offers functionality to remotely: Execute arbitrary commands; Terminate processes; Uninstall software; View event logs; Start / Stop services; Install Windows updates. Additionally, ConnectWise Control allows an operator to take control of a machine's desktop session.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote access software abused in this campaign: installed/launched via the WinDesk.Client.exe infection chain, culminating in a client service that attempts to establish a connection to attacker infrastructure (104.168.5[.]29 / firsto[.]cc), enabling remote access and potential data capture (the content notes keystroke recording potential).
Legitimate remote access/RMM tool (ScreenConnect) abused for persistence and remote administration of victim hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.