Phishing Campaigns Deliver Signed ScreenConnect Clients for Remote Access
Attackers phish victims into running legitimately signed ScreenConnect clients, including via fake invoices and Power BI links, to obtain remote access without a product flaw.
Reports from 5 October 2026 describe an invoice-themed phishing email that claimed a $5,745.65 payment or offered a PDF but linked to ScreenConnect.ClientSetup.exe on thelittlecupandsaucer.com.au, with the displayed sender given as contact@mejuri.com. The file was an authentic ConnectWise-signed ScreenConnect client, unknown on VirusTotal and with no tampering reported, preconfigured to connect over TCP 443 to an attacker-controlled cloud relay; sources disagree on the hostname, citing either instance-v2e2-relay.screenconnect.com or instance-v2e3e2-relay.screenconnect.com while both associate the setup with instance v2e3e2. Microsoft said no ScreenConnect vulnerability was exploited, and Internet Storm Center researcher Xavier Mertens described a single observed attempt with no confirmed victim count, stolen data, or named group. Separately, Microsoft documented phishing that delivered MSP360 installers to install ScreenConnect as a second remote-access channel. On 7 October, Huntress reported a related but distinct campaign active from about 10 September that used legitimate app.powerbi.com links to bypass filters, fingerprint browsers, send telemetry to a Telegram bot, and auto-download a rogue ScreenConnect client from a hamham27 tenant; a script then installed a second instance and often uninstalled the first, and one configuration was tied to 22 other endpoints.
- An invoice-themed phishing email claiming a $5,745.65 payment (subject reported as “EFT Wire Transfer”) linked to ScreenConnect.ClientSetup.exe on thelittlecupandsaucer.com.au; the displayed sender was contact@mejuri.com.
- The installer was a legitimate ConnectWise-signed ScreenConnect client (DigiCert G4 Code Signing CA1 in one report), unknown on VirusTotal with no tampering found, and preset to call an attacker relay on TCP 443.
- Sources disagree on the relay hostname: one cites instance-v2e2-relay.screenconnect.com while naming instance v2e3e2; another cites instance-v2e3e2-relay.screenconnect.com for instance v2e3e2.
- Microsoft said no ScreenConnect vulnerability was exploited. Internet Storm Center researcher Xavier Mertens described one observed attempt, with no victim count, stolen data, or named threat group.
- Microsoft separately documented phishing-delivered MSP360 installers used to deploy ScreenConnect as a second remote-access channel for file transfer, payload execution, and credential access.
- Huntress (2026-10-07) reported a campaign active from about 2026-09-10 that used legitimate app.powerbi.com links, browser fingerprinting, and Telegram telemetry to auto-download a ScreenConnect installer from a hamham27 tenant.
- In that activity a CMD and PowerShell script installed a second ScreenConnect instance and often removed the first; one related client configuration was linked to 22 additional endpoints.
- Similar abuse has been reported for AnyDesk, TeamViewer, LogMeIn, BeyondTrust, Zoho Assist, Remote Utilities, NetSupport Manager, and SimpleHelp.
Coverage timelineoldest first · each row is one article
- · 3d agoAttackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
GBHackers· 56
Phishers deliver a legitimately signed ConnectWise ScreenConnect client preconfigured to call back to attacker infrastructure, bypassing malware detection for remote access.
- · 3d agoHackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing
Cyber Security News· 54
Phishers sent a fake payment notice that installed a legitimate ScreenConnect client aimed at their server.
- · 1d ago