ZeroHour
Vendor

ScreenConnect

1 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Phishing emails with browser-in-the-browser fake Adobe pages trick users into installing rogue ScreenConnect clients granting persistent remote access.

Huntress SOC investigated two August incidents where phishing links led to fake CAPTCHA checks and Adobe PDF Reader lures rendered as browser-in-the-browser (BiTB) pages spoofing legitimate domains like get.adobe.com. Victims downloaded what they believed was Acrobat Reader but actually installed ScreenConnect.ClientSetup.exe from attacker infrastructure, yielding two rogue ScreenConnect clients with service-based persistence. The attacker used cmd.exe and curl to stage a second client connecting to 144.172.115.59, leveraged a ScreenConnect Trial Relay domain for stealth, and ran HideCursor.exe as a defense-evasion binary. Incident 2 arrived via AT&T Office@Hand (RingCentral), with both chains stopped before broader impact.

Huntress · 6d agoPhishing & fraud in the wild

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Threat actors chain multiple legitimate Google service redirects to evade detection and deliver credential harvesting or ScreenConnect remote access tooling.

Threat actors are abusing multiple legitimate Google services to build multi-hop redirect chains that obscure the final destination and bypass reputation-based filtering. The campaign culminates in credential harvesting pages or silent installation of the ScreenConnect remote access tool. Defenders should watch for links that traverse trusted Google domains before landing on malicious endpoints.

Dark Reading · 7d agoPhishing & fraud in the wild

ConnectWise warns of new ScreenConnect flaw without patch

ConnectWise warns of an unpatched ScreenConnect flaw affecting file transfer in support sessions and shares interim mitigations for MSPs.

ConnectWise disclosed a new ScreenConnect Remote Access vulnerability affecting file transfer behavior in both cloud and on-premises deployments; no CVE ID or patch is available yet, with a fix planned later this week. The vendor published temporary mitigation steps that remove TransferFiles permissions from session groups across all roles. Shadowserver tracks nearly 6,000 internet-exposed ScreenConnect instances. Previous ScreenConnect flaws, including CVE-2024-1709, were exploited by ransomware gangs and North Korea's Kimsuky, and three ScreenConnect vulnerabilities are on CISA's actively exploited catalog.

Medusa ransomware gang has hit over 500 organizations, CISA warns

FBI, CISA, and HHS warn Medusa ransomware has hit over 500 organizations across critical infrastructure since June 2021, using phishing and unpatched flaws.

An updated joint advisory from CISA, FBI, and HHS states Medusa ransomware has affected more than 500 organizations, spanning healthcare, defense, manufacturing, government, IT, financial services, education, insurance, and legal sectors. Since early 2023 Medusa has operated a ransomware-as-a-service affiliate model and buys access from initial access brokers for $100 to $1 million. Affiliates gain entry via phishing and unpatched internet-facing software, exploiting newly disclosed flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust within 24 hours. The group runs double extortion, giving victims 48 hours before leak-site publication, with $10,000 in cryptocurrency buying a one-day delay.

Help Net Security · 28d agoRansomware in the wild

Related CVEs

  • Authentication Bypass in ConnectWise ScreenConnect Creates Rogue Admin Accounts
    ConnectWise ScreenConnect (ConnectWise Control), a widely used remote-access and remote-monitoring tool, contains an authentication bypass (CWE-288) in its management interface. An attacker needs only network access to the management interface to trigger the flaw, with no valid credentials or user interaction required. A successful attacker gains administrative control of the ScreenConnect server by creating a new administrator-level account, providing a foothold that has already been used in ransomware campaigns against downstream managed environments. Any organization running ConnectWise ScreenConnect is affected, especially managed service providers and IT teams whose management interface is reachable from the internet; the source data specifies affected products but no version ranges. Exploitation is confirmed and urgent: CISA added the flaw to the KEV on 2024-02-22 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days, and ConnectWise warned that no patch was available at the time of disclosure.
    · ConnectWise ScreenConnect KEV ransomware PoC ×3mass
  • ViewState Code Injection in ConnectWise ScreenConnect May Lead to RCE
    ConnectWise ScreenConnect versions 25.2.3 and earlier rely on ASP.NET Web Forms ViewState, whose integrity depends on machine keys; if an attacker with privileged system-level access obtains those keys, they can craft and send a malicious ViewState that the server deserializes, potentially resulting in remote code execution. The risk stems from platform-level ASP.NET behavior rather than a defect introduced by ScreenConnect, and the ScreenConnect Client is not directly impacted, though the CVSS vector (PR:H) confirms exploitation requires already having high privileges on the host. An attacker who achieves this gains code execution on the server with the confidentiality, integrity, and availability impact reflected in the 7.2 High score. ScreenConnect 2025.4 mitigates the issue by disabling ViewState entirely and removing any dependency on it. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-02, indicating confirmed exploitation in the wild, with EPSS estimating a 3.4% chance of exploitation in the next 30 days (88th percentile).
    · ConnectWise ScreenConnect 25.2.3 and earlier; mitigated in 2025.4 (ViewState disabled) KEVlarge
  • A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauth
    A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.