Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
Phishers deliver a legitimately signed ConnectWise ScreenConnect client preconfigured to call back to attacker infrastructure, bypassing malware detection for remote access.
An invoice-themed phishing email (subject 'EFT Wire Transfer', fake $5,745.65 payment pretext) directed victims via a hyperlink to a ScreenConnect.ClientSetup.exe hosted on thelittlecupandsaucer.com.au. The executable was an authentic ScreenConnect client validly signed by ConnectWise, LLC through DigiCert G4 Code Signing CA1, but configured to contact the attacker-operated relay instance-v2e2-relay.screenconnect.com over TCP 443 (instance v2e3e2), granting remote desktop control after execution. Microsoft confirmed no ScreenConnect vulnerability was exploited and separately documented phishing-delivered MSP360 installers used to deploy ScreenConnect as a second remote-access channel for file transfer, payload execution, and credential access. Attackers have similarly abused AnyDesk, TeamViewer, LogMeIn, BeyondTrust, Zoho Assist, Remote Utilities, NetSupport Manager, and SimpleHelp.