Threat actors including Black Basta have been actively exploiting recent ConnectWise ScreenConnect vulnerabilities to gain access to victim environments, then using that foothold to deepen control and prepare for follow-on attacks. Trend Micro reported post-compromise reconnaissance against domain controllers, including enumeration of domain computers, trusts, domain controllers, and local administrators, indicating efforts to map enterprise networks and identify privileged access.
Attackers were also observed deploying additional remote management tools to maintain persistence and broaden remote access. In compromised environments, they abused BITSAdmin to download and execute another ScreenConnect client from transfer[.]sh, and in several European targets—mostly in Belgium—they installed trial versions of Atera RMM using msiexec parameters linked to an Outlook email account and account identifiers. Researchers warned that the activity could quickly progress to ransomware deployment, data theft, operational disruption, and financial losses, making immediate patching to the latest ScreenConnect version critical.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Trend Micro warned that exploitation of the ScreenConnect flaws could lead to ransomware deployment, data compromise, operational disruption, and financial loss. The company advised organizations to immediately update to the latest ScreenConnect version.
In observed intrusions, attackers ran reconnaissance commands against domain controllers to enumerate domain computers, trusts, domain controllers, and local administrators. They also abused BITSAdmin to download and execute another ScreenConnect client from transfer[.]sh and deployed trial Atera RMM instances at several mostly Belgian European targets using msiexec.
By late February 2024, Trend Micro observed threat actor groups, including Black Basta, exploiting recently disclosed ConnectWise ScreenConnect vulnerabilities in the wild. The activity showed attackers gaining access to compromised environments and using that foothold for follow-on intrusion activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.