Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are using a legitimate ScreenConnect client to turn a payment notification into a route for remote access. Instead of delivering custom malware, the phishing attempt directs recipients to software already designed to let someone else connect to their computer.

The email claims that a payment of $5745.65 has been received and invites the recipient to view order information as a PDF.

This resembles earlier remote access phishing lures that disguise administrative software as everyday documents or familiar workplace downloads. Researchers from Internet Storm Center identified the abuse after examining the downloaded program.

Internet Storm Center said in a report shared with Cyber Security News (CSN) that the file was a legitimate client configured to contact an attacker-operated test account.

Published on October 1, 2026, the analysis by Xavier Mertens describes an observed phishing attempt, not a confirmed large-scale breach.

It provides no victim count or evidence of stolen data, but highlights how legitimate remote support software can become an entry point when attackers control its configuration.

Hackers Abuse Legitimate ScreenConnect Tool

The message uses a wire transfer subject and a paid invoice receipt format to make the request look routine. It also offers cancellation and an immediate refund if the charge was unauthorized, giving recipients another reason to investigate an unexpected transaction.

The central deception is straightforward: the promised PDF is actually a Windows executable. Following the link downloads a ScreenConnect installer rather than the advertised order document. The attack therefore depends on persuading a recipient to run software delivered through an unsolicited financial message.

Mertens reported that the email passed basic security controls. He also noted that browsers would block this delivery approach because downloading an executable is suspicious.

The report does not establish that a recipient bypassed that protection or successfully installed the client on a victim system.

Configuration extracted from the PE file (Source - Internet Storm Center)
Configuration extracted from the PE file (Source – Internet Storm Center)

The technique echoes legitimate RMM phishing campaigns that use trusted remote management applications instead of a recognizable malicious payload.

However, the ISC report does not connect this particular email to those operations or attribute it to a named threat group. The downloaded file was unknown on VirusTotal when Mertens examined it.

His analysis found a preconfigured connection to a specific cloud-hosted ScreenConnect instance, using port 443. That configuration would direct the client toward the attacker’s account rather than an organization’s approved support environment.

Detection Challenges

The executable carried a digital signature from ConnectWise, LLC, issued through DigiCert G4 Code Signing CA1. Its Authenticode digest matched the signed digest exactly, meaning the checked file content corresponded to what the publisher had signed.

Mertens also found no extra data appended to the executable and no additions or injections in its certificate table. He explicitly ruled out a signed-but-tampered configuration trick.

The finding matters because the suspicious behavior came from the software’s intended remote access function, not an altered binary. The case illustrates a gap between identifying a program and deciding whether its use is actually safe.

Here, the software was genuine, but the email misrepresented what the recipient would receive. The relevant question is who arranged the installation and which remote account the client is configured to ultimately reach after it starts.

For defenders, that distinction changes the investigation. Earlier reporting on detecting trusted tool abuse explains why download context, user expectations, execution activity, and subsequent connections matter together.

A legitimate installer does not, by itself, prove that the resulting remote session was authorized. The ISC report points readers to the LOLRMM project for a broader inventory of remote management tools that attackers can misuse.

Its wider message is that familiar support applications deserve scrutiny when their installation follows an unexpected email rather than a verified support request.

The indicators below come from the ISC report, not the separate campaigns linked for context. The published key hash is abbreviated, so it cannot serve as a complete SHA-256 matching value.

The relay is legitimate cloud infrastructure associated with the observed configuration, not evidence that every ScreenConnect connection is malicious.

Indicators of compromise (IoCs):-

Type Indicator Description
Sender email contact@mejuri[.]com Address displayed in the phishing email’s From field; the report does not establish ownership or sender authenticity.
Sender domain mejuri[.]com Domain appearing in the displayed sender address.
Download URL hxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe Defanged destination of the email’s document-viewing link, delivering the executable.
Download domain thelittlecupandsaucer[.]com[.]au Domain hosting the linked ScreenConnect installer.
File name ScreenConnect.ClientSetup.exe Executable delivered instead of the promised PDF.
Relay hostname instance-v2e3e2-relay.screenconnect.com Legitimate ScreenConnect relay specified in the attacker-configured client.
Network port 443 Connection port extracted from the client configuration; not independently malicious.
Instance ID v2e3e2 ConnectWise-hosted cloud instance identified in the configuration.
Abbreviated SHA-256 16b1cec1…9b00ead7 Published fragment of the RSA-2048 public-key blob hash. This is not a complete hash or an executable hash.
Telephone number +1(332)638474823 Customer-support number displayed in the phishing message, reproduced exactly as published.
Contextual file name rutserv.exe Listed only as an example of another remote utility; not reported as a payload in this attempt.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing appeared first on Cyber Security News.