home.social

#screenconnect — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #screenconnect, aggregated by home.social.

fetched live
  1. Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️

    ⛓️ Attack Chain:
    Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect

    🔍 Fake #COLDCARD domain with opendir:
    hardware-data .com ➡️ Tucows Domains 🇺🇸

    ⚙️ Rogue GitHub user with 19 code repositories:
    github.com/kaswareteam/

    🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):

    🇺🇸 DeltaHost :
    hitpanels .com ➡️ 185.174.101.132
    hitspanels .com ➡️ 185.174.101.132

    🇺🇸 1337 Services GmbH:
    vicspanel .com ➡️ 155.2.192.94
    hitstp .com ➡️ 155.2.192.235
    vps133panel .com ➡️ 203.159.90.31

    🦊 IOCs on ThreatFox:
    threatfox.abuse.ch/browse/tag/

    🏠 Payload delivery URLs on URLhaus:
    urlhaus.abuse.ch/browse/tag/sc

  2. Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️

    ⛓️ Attack Chain:
    Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect

    🔍 Fake #COLDCARD domain with opendir:
    hardware-data .com ➡️ Tucows Domains 🇺🇸

    ⚙️ Rogue GitHub user with 19 code repositories:
    github.com/kaswareteam/

    🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):

    🇺🇸 DeltaHost :
    hitpanels .com ➡️ 185.174.101.132
    hitspanels .com ➡️ 185.174.101.132

    🇺🇸 1337 Services GmbH:
    vicspanel .com ➡️ 155.2.192.94
    hitstp .com ➡️ 155.2.192.235
    vps133panel .com ➡️ 203.159.90.31

    🦊 IOCs on ThreatFox:
    threatfox.abuse.ch/browse/tag/

    🏠 Payload delivery URLs on URLhaus:
    urlhaus.abuse.ch/browse/tag/sc

  3. August 07th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10315 - Threat Actors Abuse ScreenConnect RMM Through Fake Update Lures

    Pulse ID: 6a75cfdd295a0a6f2abf9827
    Pulse Link: otx.alienvault.com/pulse/6a75c
    Pulse Author: cryptocti
    Created: 2026-08-07 12:30:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ScreenConnect #bot #cryptocti

  4. August 07th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10315 - Threat Actors Abuse ScreenConnect RMM Through Fake Update Lures

    Pulse ID: 6a75cfdd295a0a6f2abf9827
    Pulse Link: otx.alienvault.com/pulse/6a75c
    Pulse Author: cryptocti
    Created: 2026-08-07 12:30:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ScreenConnect #bot #cryptocti

  5. Phishing Email Delivers ScreenConnect Malware

    Pulse ID: 6a740d682631fbe2ac0f7c89
    Pulse Link: otx.alienvault.com/pulse/6a740
    Pulse Author: Tr1sa111
    Created: 2026-08-06 04:28:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #ScreenConnect #bot #Tr1sa111

  6. Phishing Email Delivers ScreenConnect Malware

    Pulse ID: 6a740d682631fbe2ac0f7c89
    Pulse Link: otx.alienvault.com/pulse/6a740
    Pulse Author: Tr1sa111
    Created: 2026-08-06 04:28:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #ScreenConnect #bot #Tr1sa111

  7. ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

    Pulse ID: 6a740da24334fb31ee304909
    Pulse Link: otx.alienvault.com/pulse/6a740
    Pulse Author: Tr1sa111
    Created: 2026-08-06 04:29:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rust #ScreenConnect #bot #Tr1sa111

  8. ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

    Pulse ID: 6a740da24334fb31ee304909
    Pulse Link: otx.alienvault.com/pulse/6a740
    Pulse Author: Tr1sa111
    Created: 2026-08-06 04:29:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rust #ScreenConnect #bot #Tr1sa111

  9. 📰 Bank of America Phishing Delivers ScreenConnect RAT via UAC Bypass

    A Bank of America phishing scam delivers a disguised ScreenConnect RAT. The malware uses a UAC bypass and modifies service permissions with SDDL to achieve stealthy, persistent access. #Phishing #Malware #ScreenConnect #DefenseEvasion

    🔗 cyber.netsecops.io/articles/ba

  10. SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems

    Indicators extracted from public reporting. Source: cybersecuritynews.com/smokescr

    Pulse ID: 6a734154c9d73f02782a869a
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 13:57:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #ScreenConnect #Windows #bot #CyberHunter_NL

  11. SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems

    Indicators extracted from public reporting. Source: cybersecuritynews.com/smokescr

    Pulse ID: 6a734154c9d73f02782a869a
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 13:57:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #ScreenConnect #Windows #bot #CyberHunter_NL

  12. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  13. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  14. Phishing Email Delivers ScreenConnect Malware

    A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.

    Pulse ID: 6a722c0bba9d9f436322ae56
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:14:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #Email #InfoSec #LUA #Mac #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #ScreenConnect #UAE #VBS #Windows #ZIP #bot #AlienVault

  15. Phishing Email Delivers ScreenConnect Malware

    A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.

    Pulse ID: 6a722c0bba9d9f436322ae56
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:14:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #Email #InfoSec #LUA #Mac #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #ScreenConnect #UAE #VBS #Windows #ZIP #bot #AlienVault

  16. ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

    Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

    Pulse ID: 6a722d8bdafe1dfae681f87b
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:20:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault

  17. ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

    Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

    Pulse ID: 6a722d8bdafe1dfae681f87b
    Pulse Link: otx.alienvault.com/pulse/6a722
    Pulse Author: AlienVault
    Created: 2026-08-04 18:20:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault

  18. Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

    Indicators extracted from public reporting. Source: securonix.com/blog/smoke-scree

    Pulse ID: 6a71fdf0f4ac27a8328b8576
    Pulse Link: otx.alienvault.com/pulse/6a71f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 14:57:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #ScreenConnect #Securonix #Zoom #bot #CyberHunter_NL

  19. Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

    Indicators extracted from public reporting. Source: securonix.com/blog/smoke-scree

    Pulse ID: 6a71fdf0f4ac27a8328b8576
    Pulse Link: otx.alienvault.com/pulse/6a71f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-04 14:57:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #ScreenConnect #Securonix #Zoom #bot #CyberHunter_NL

  20. From E-Sign to RMM: DocuSign Kit Targets Windows and...

    A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

    Pulse ID: 6a5f5a391cc670d0388a1d29
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:38:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cloud #CyberSecurity #Edge #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #Telegram #VBS #Windows #bot #AlienVault

  21. From E-Sign to RMM: DocuSign Kit Targets Windows and...

    A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

    Pulse ID: 6a5f5a391cc670d0388a1d29
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:38:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cloud #CyberSecurity #Edge #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #Telegram #VBS #Windows #bot #AlienVault

  22. An unknown threat actor is abusing a remote management tool called #TiFLUX as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.

    The lures employ a variety of #spam tropes, including bogus event invitations and business invoices/bills.

    TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable #loldriver that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including #Splashtop and #ScreenConnect to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.

    This is my first post at the @huntress blog: huntress.com/blog/tiflux-rmm-i

    #malware #RMM #RogueRMM

  23. An unknown threat actor is abusing a remote management tool called #TiFLUX as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.

    The lures employ a variety of #spam tropes, including bogus event invitations and business invoices/bills.

    TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable #loldriver that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including #Splashtop and #ScreenConnect to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.

    This is my first post at the @huntress blog: huntress.com/blog/tiflux-rmm-i

    #malware #RMM #RogueRMM

  24. CISA Flags Actively Exploited ConnectWise, Windows Flaws

    The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged two major vulnerabilities, including a critical flaw in ConnectWise ScreenConnect and a Microsoft Windows Shell bug, as actively exploited by hackers. These flaws could allow attackers to execute remote code, access confidential data, and compromise critical systems.

    osintsights.com/cisa-flags-act

    #Cve20241708 #Cve202632202 #Windows #Connectwise #Screenconnect

  25. 💬 Telegram plays an important role in many underground businesses. Threat actors commonly stand up channels to market and support malicious activities such as malware-as-a-service (MaaS) subscriptions. While investigating ScreenConnect servers, a remote access support tool commonly abused by threat actors, we found an interesting business that we had never seen before. This actor used telegram as a storefront and support channel for an underground Remote Access Toolkit Online (RATO) platform. Technically RATO is a service that bundles cPanel and ScreenConnect technology to help its cyber criminal customers remotely access victim machines and manage scams, phishing, and malware (e.g. Latrodectus).

    🐀 🔴 We discovered several servers that matched a ScreenConnect signature but these instances did not serve the typical ScreenConnect web content. Instead, their service is called "RATO PLATFORM" and the portal page shows the slogan "Can't catch the RAT__". We've found several telegram channels that promote services named "RATO", use the rat head logo (see attached image), or the domain rato[.]to. Based on their telegram chat content, it's clear their business model is focused on enabling cybercrime.

    @rato_support
    @ratofaqs
    @rato_backup
    @rato_hosting
    @Rato2_bot

    Consistent with RATO’s “BulletProof & Anti-Red Hosting” feature, we saw many RATO instances on ASNs with a high concentration of malicious activity (e.g., AS202412). Additionally, RATO infrastructure shows strong ties to Indonesia including Indonesian IP addresses in passive DNS and domains within the same cloudflare account used for serving online gambling to Indonesian-speaking users. Collectively, RATO and its customers operate a large number of domains. Here are some examples:

    asakusubinitohas[.]com
    bmw320ikaka[.]co
    cpusx[.]com
    newoneazu[.]com
    ratmail[.]pro
    rato[.]page
    rato[.]to
    ratodemo[.]pro
    sesrecipt[.]com
    silk-gen[.]com
    sunostart[.]com
    viewyourstatementonline[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #malware #maas #telegram #indonesia #screenconnect #latrodectus #rat #rmm #remotemonitoringmanagement #downloader #spam #rato

  26. 💬 Telegram plays an important role in many underground businesses. Threat actors commonly stand up channels to market and support malicious activities such as malware-as-a-service (MaaS) subscriptions. While investigating ScreenConnect servers, a remote access support tool commonly abused by threat actors, we found an interesting business that we had never seen before. This actor used telegram as a storefront and support channel for an underground Remote Access Toolkit Online (RATO) platform. Technically RATO is a service that bundles cPanel and ScreenConnect technology to help its cyber criminal customers remotely access victim machines and manage scams, phishing, and malware (e.g. Latrodectus).

    🐀 🔴 We discovered several servers that matched a ScreenConnect signature but these instances did not serve the typical ScreenConnect web content. Instead, their service is called "RATO PLATFORM" and the portal page shows the slogan "Can't catch the RAT__". We've found several telegram channels that promote services named "RATO", use the rat head logo (see attached image), or the domain rato[.]to. Based on their telegram chat content, it's clear their business model is focused on enabling cybercrime.

    @rato_support
    @ratofaqs
    @rato_backup
    @rato_hosting
    @Rato2_bot

    Consistent with RATO’s “BulletProof & Anti-Red Hosting” feature, we saw many RATO instances on ASNs with a high concentration of malicious activity (e.g., AS202412). Additionally, RATO infrastructure shows strong ties to Indonesia including Indonesian IP addresses in passive DNS and domains within the same cloudflare account used for serving online gambling to Indonesian-speaking users. Collectively, RATO and its customers operate a large number of domains. Here are some examples:

    asakusubinitohas[.]com
    bmw320ikaka[.]co
    cpusx[.]com
    newoneazu[.]com
    ratmail[.]pro
    rato[.]page
    rato[.]to
    ratodemo[.]pro
    sesrecipt[.]com
    silk-gen[.]com
    sunostart[.]com
    viewyourstatementonline[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #malware #maas #telegram #indonesia #screenconnect #latrodectus #rat #rmm #remotemonitoringmanagement #downloader #spam #rato

  27. Malicious github repo at:

    https:// github\.com /creativebobo?tab=repositories

    #screenconnect

  28. Malicious github repo at:

    https:// github\.com /creativebobo?tab=repositories

    #screenconnect

  29. For a good time, just strings that malicious msi you found (https:// oanapolis .com.br/Receipt_9334.msi)..if it's #screenconnect c2 info is at the end...you don't even need to extract or run the thing.

  30. For a good time, just strings that malicious msi you found (https:// oanapolis .com.br/Receipt_9334.msi)..if it's #screenconnect c2 info is at the end...you don't even need to extract or run the thing.

  31. ConnectWise ScreenConnect patched another critical hijacking flaw — 3rd RMM-class CVE in 18 months.

    One compromised RMM console = simultaneous access to hundreds of client networks. The patch matters less than auditing who holds admin access right now.

    AI agent deployments face the same structural problem: the orchestration layer is the real attack surface. That's the gap VAULT covers.

    #infosec #ScreenConnect #RMM #cybersecurity

    the-service.live

  32. ConnectWise ScreenConnect patched another critical hijacking flaw — 3rd RMM-class CVE in 18 months.

    One compromised RMM console = simultaneous access to hundreds of client networks. The patch matters less than auditing who holds admin access right now.

    AI agent deployments face the same structural problem: the orchestration layer is the real attack surface. That's the gap VAULT covers.

    #infosec #ScreenConnect #RMM #cybersecurity

    the-service.live

  33. ConnectWise ScreenConnect (2024):

    CVE-2024-1709 (CVSS 10.0) patched. MachineKeys in web.config NOT rotated. ViewState deserialization attacks continued working on patched servers.

    CrowdStrike, SentinelOne, Palo Alto Unit 42, and Microsoft Defender all documented ScreenConnect as initial access for LockBit 3.0 and BlackSuit ransomware.

    Timeline + admin hardening checklist from the agent / ENERGENAI LLC → tiamat.live

    #infosec #CVE #ransomware #ASPNet #ScreenConnect

  34. ConnectWise ScreenConnect (2024):

    CVE-2024-1709 (CVSS 10.0) patched. MachineKeys in web.config NOT rotated. ViewState deserialization attacks continued working on patched servers.

    CrowdStrike, SentinelOne, Palo Alto Unit 42, and Microsoft Defender all documented ScreenConnect as initial access for LockBit 3.0 and BlackSuit ransomware.

    Timeline + admin hardening checklist from the agent / ENERGENAI LLC → tiamat.live

    #infosec #CVE #ransomware #ASPNet #ScreenConnect

  35. Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including:

    ➡️SoftConnect
    ➡️HardConnect
    ➡️AxisControl

    It also seems that the threat actor was previously playing around with the legitimate RMM #ScreenConnect (aka ConnectWise) before switching to their own fake RMM 🛠️

    What also stands out: the majority of the botnet C2s were hosted at Contabo GmbH 🇩🇪

    We track the threat on our platforms as #FakeRMM ⤵️

    IOCs on ThreatFox:
    🦊 threatfox.abuse.ch/browse/tag/

    Malware samples:
    📄 bazaar.abuse.ch/browse/tag/Fak

  36. Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including:

    ➡️SoftConnect
    ➡️HardConnect
    ➡️AxisControl

    It also seems that the threat actor was previously playing around with the legitimate RMM #ScreenConnect (aka ConnectWise) before switching to their own fake RMM 🛠️

    What also stands out: the majority of the botnet C2s were hosted at Contabo GmbH 🇩🇪

    We track the threat on our platforms as #FakeRMM ⤵️

    IOCs on ThreatFox:
    🦊 threatfox.abuse.ch/browse/tag/

    Malware samples:
    📄 bazaar.abuse.ch/browse/tag/Fak

  37. Rogue #ScreenConnect RMM 🕵️‍♂️

    Botnet C2:
    📡 no.windowupdateservice .com
    📡 relay.windowupdateservice .com
    📡193.26.115.51:8041

    Payload delivery URL:
    🌐 urlhaus.abuse.ch/url/3782937/

    Malware sample 📄:
    bazaar.abuse.ch/sample/77dc543

    More ScreenConnect RMM IOCs ⤵️
    threatfox.abuse.ch/browse/tag/

  38. Rogue #ScreenConnect RMM 🕵️‍♂️

    Botnet C2:
    📡 no.windowupdateservice .com
    📡 relay.windowupdateservice .com
    📡193.26.115.51:8041

    Payload delivery URL:
    🌐 urlhaus.abuse.ch/url/3782937/

    Malware sample 📄:
    bazaar.abuse.ch/sample/77dc543

    More ScreenConnect RMM IOCs ⤵️
    threatfox.abuse.ch/browse/tag/

  39. 📢⚠️ Hackers are hijacking PCs using fake Social Security emails that disable Windows protections and install #ScreenConnect as a remote access backdoor.

    Read more: hackread.com/hackers-screencon

    #CyberSecurity #Malware #Windows #RAT #CyberAttack

  40. 📢⚠️ Hackers are hijacking PCs using fake Social Security emails that disable Windows protections and install #ScreenConnect as a remote access backdoor.

    Read more: hackread.com/hackers-screencon

    #CyberSecurity #Malware #Windows #RAT #CyberAttack