Attackers Distributed Malicious ScreenConnect Clients

Phishing emails leveraged legitimate remote management software to gain unauthorized access to user systems.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of a glowing digital portal and a geometric key, representing unauthorized remote system access.
Threat actors are leveraging legitimate ScreenConnect remote access software in a new phishing campaign to gain unauthorized control of target systems. AI Illustration. Upload story photo >

Live Poll

Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?

Threat actors have launched a phishing campaign using fake wire transfer receipts to trick users into downloading malicious ScreenConnect client installers. The attackers utilize legitimate, digitally signed software to bypass traditional security detection mechanisms.

Why it matters

By repurposing trusted remote monitoring tools, attackers can effectively evade security software and establish unauthorized control over target devices. This method exploits the inherent trust systems place in valid digital signatures.

The malicious executable, ScreenConnect.ClientSetup.exe, utilizes a legitimate digital signature from ConnectWise, LLC. While the file escaped initial detection on VirusTotal, browser-based security protocols correctly flagged the download attempt.

The players

ConnectWise, LLC

This company develops the ScreenConnect software, which is a legitimate remote monitoring and management tool frequently used by IT professionals.

The details

The campaign relies on phishing emails that masquerade as electronic fund transfer receipts to lure targets into clicking a download link. Once executed, the preconfigured ScreenConnect client connects directly to an attacker-controlled account, granting them remote access to the host machine.

Timeline

  1. October 1, 2026: The phishing campaign was identified and reported.

The Tech Race

This incident highlights an ongoing arms race where attackers weaponize legitimate remote management tools cataloged in the LOLRMM project to evade security filters. The exploit signifies a shift from traditional malware toward the abuse of trusted, pre-installed administrative utilities.

Users should exercise extreme caution with unsolicited emails containing invoices or wire transfer receipts, especially those from unfamiliar senders. Always verify the authenticity of download links for administrative tools and ensure your browser's security features remain enabled to catch potential threats.

The takeaway

Cybersecurity requires constant vigilance against tools that appear legitimate but serve malicious purposes. Organizations and individuals should treat all unexpected software downloads as potential threats regardless of digital signatures.

Further reading

For more information on the misuse of administrative software, visit our Cybersecurity section.

More information

Review the full list of tools used in similar unauthorized access campaigns on the LOLRMM project remote management tool list.

Source note: This article includes information reported by SANS Internet Storm Center.

Live Poll

Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?