Attackers Distributed Malicious ScreenConnect Clients
Phishing emails leveraged legitimate remote management software to gain unauthorized access to user systems.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?
Threat actors have launched a phishing campaign using fake wire transfer receipts to trick users into downloading malicious ScreenConnect client installers. The attackers utilize legitimate, digitally signed software to bypass traditional security detection mechanisms.
Why it matters
By repurposing trusted remote monitoring tools, attackers can effectively evade security software and establish unauthorized control over target devices. This method exploits the inherent trust systems place in valid digital signatures.
The malicious executable, ScreenConnect.ClientSetup.exe, utilizes a legitimate digital signature from ConnectWise, LLC. While the file escaped initial detection on VirusTotal, browser-based security protocols correctly flagged the download attempt.
The players
ConnectWise, LLC
This company develops the ScreenConnect software, which is a legitimate remote monitoring and management tool frequently used by IT professionals.
The details
The campaign relies on phishing emails that masquerade as electronic fund transfer receipts to lure targets into clicking a download link. Once executed, the preconfigured ScreenConnect client connects directly to an attacker-controlled account, granting them remote access to the host machine.
Timeline
October 1, 2026: The phishing campaign was identified and reported.
The Tech Race
This incident highlights an ongoing arms race where attackers weaponize legitimate remote management tools cataloged in the LOLRMM project to evade security filters. The exploit signifies a shift from traditional malware toward the abuse of trusted, pre-installed administrative utilities.
Users should exercise extreme caution with unsolicited emails containing invoices or wire transfer receipts, especially those from unfamiliar senders. Always verify the authenticity of download links for administrative tools and ensure your browser's security features remain enabled to catch potential threats.
The takeaway
Cybersecurity requires constant vigilance against tools that appear legitimate but serve malicious purposes. Organizations and individuals should treat all unexpected software downloads as potential threats regardless of digital signatures.
Further reading
For more information on the misuse of administrative software, visit our Cybersecurity section.
More information
Review the full list of tools used in similar unauthorized access campaigns on the LOLRMM project remote management tool list.
Source note: This article includes information reported by SANS Internet Storm Center.
Live Poll
Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?







