#screenconnect — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #screenconnect, aggregated by home.social.
-
Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️
⛓️ Attack Chain:
Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect🔍 Fake #COLDCARD domain with opendir:
hardware-data .com ➡️ Tucows Domains 🇺🇸⚙️ Rogue GitHub user with 19 code repositories:
https://github.com/kaswareteam/🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):
🇺🇸 DeltaHost :
hitpanels .com ➡️ 185.174.101.132
hitspanels .com ➡️ 185.174.101.132🇺🇸 1337 Services GmbH:
vicspanel .com ➡️ 155.2.192.94
hitstp .com ➡️ 155.2.192.235
vps133panel .com ➡️ 203.159.90.31🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/tag/ScreenConnect/🏠 Payload delivery URLs on URLhaus:
https://urlhaus.abuse.ch/browse/tag/screenconnect/ -
Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️
⛓️ Attack Chain:
Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect🔍 Fake #COLDCARD domain with opendir:
hardware-data .com ➡️ Tucows Domains 🇺🇸⚙️ Rogue GitHub user with 19 code repositories:
https://github.com/kaswareteam/🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):
🇺🇸 DeltaHost :
hitpanels .com ➡️ 185.174.101.132
hitspanels .com ➡️ 185.174.101.132🇺🇸 1337 Services GmbH:
vicspanel .com ➡️ 155.2.192.94
hitstp .com ➡️ 155.2.192.235
vps133panel .com ➡️ 203.159.90.31🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/tag/ScreenConnect/🏠 Payload delivery URLs on URLhaus:
https://urlhaus.abuse.ch/browse/tag/screenconnect/ -
August 07th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10315 - Threat Actors Abuse ScreenConnect RMM Through Fake Update Lures
Pulse ID: 6a75cfdd295a0a6f2abf9827
Pulse Link: https://otx.alienvault.com/pulse/6a75cfdd295a0a6f2abf9827
Pulse Author: cryptocti
Created: 2026-08-07 12:30:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ScreenConnect #bot #cryptocti
-
August 07th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10315 - Threat Actors Abuse ScreenConnect RMM Through Fake Update Lures
Pulse ID: 6a75cfdd295a0a6f2abf9827
Pulse Link: https://otx.alienvault.com/pulse/6a75cfdd295a0a6f2abf9827
Pulse Author: cryptocti
Created: 2026-08-07 12:30:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ScreenConnect #bot #cryptocti
-
Phishing Email Delivers ScreenConnect Malware
Pulse ID: 6a740d682631fbe2ac0f7c89
Pulse Link: https://otx.alienvault.com/pulse/6a740d682631fbe2ac0f7c89
Pulse Author: Tr1sa111
Created: 2026-08-06 04:28:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #ScreenConnect #bot #Tr1sa111
-
Phishing Email Delivers ScreenConnect Malware
Pulse ID: 6a740d682631fbe2ac0f7c89
Pulse Link: https://otx.alienvault.com/pulse/6a740d682631fbe2ac0f7c89
Pulse Author: Tr1sa111
Created: 2026-08-06 04:28:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #ScreenConnect #bot #Tr1sa111
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Pulse ID: 6a740da24334fb31ee304909
Pulse Link: https://otx.alienvault.com/pulse/6a740da24334fb31ee304909
Pulse Author: Tr1sa111
Created: 2026-08-06 04:29:22Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rust #ScreenConnect #bot #Tr1sa111
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Pulse ID: 6a740da24334fb31ee304909
Pulse Link: https://otx.alienvault.com/pulse/6a740da24334fb31ee304909
Pulse Author: Tr1sa111
Created: 2026-08-06 04:29:22Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rust #ScreenConnect #bot #Tr1sa111
-
Bank of America Phishing Scam Installs Remote Access Malware - https://www.redpacketsecurity.com/fake-bank-of-america-phishing-scam-installs-remote-access-malware/
-
Bank of America Phishing Scam Installs Remote Access Malware - https://www.redpacketsecurity.com/fake-bank-of-america-phishing-scam-installs-remote-access-malware/
-
📰 Bank of America Phishing Delivers ScreenConnect RAT via UAC Bypass
A Bank of America phishing scam delivers a disguised ScreenConnect RAT. The malware uses a UAC bypass and modifies service permissions with SDDL to achieve stealthy, persistent access. #Phishing #Malware #ScreenConnect #DefenseEvasion
-
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/smokescreen-campaign/
Pulse ID: 6a734154c9d73f02782a869a
Pulse Link: https://otx.alienvault.com/pulse/6a734154c9d73f02782a869a
Pulse Author: CyberHunter_NL
Created: 2026-08-05 13:57:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #ScreenConnect #Windows #bot #CyberHunter_NL
-
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/smokescreen-campaign/
Pulse ID: 6a734154c9d73f02782a869a
Pulse Link: https://otx.alienvault.com/pulse/6a734154c9d73f02782a869a
Pulse Author: CyberHunter_NL
Created: 2026-08-05 13:57:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RCE #ScreenConnect #Windows #bot #CyberHunter_NL
-
PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.
1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b
-
PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.
1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b
-
Phishing Email Delivers ScreenConnect Malware
A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.
Pulse ID: 6a722c0bba9d9f436322ae56
Pulse Link: https://otx.alienvault.com/pulse/6a722c0bba9d9f436322ae56
Pulse Author: AlienVault
Created: 2026-08-04 18:14:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #Email #InfoSec #LUA #Mac #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #ScreenConnect #UAE #VBS #Windows #ZIP #bot #AlienVault
-
Phishing Email Delivers ScreenConnect Malware
A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads.
Pulse ID: 6a722c0bba9d9f436322ae56
Pulse Link: https://otx.alienvault.com/pulse/6a722c0bba9d9f436322ae56
Pulse Author: AlienVault
Created: 2026-08-04 18:14:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #Email #InfoSec #LUA #Mac #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #ScreenConnect #UAE #VBS #Windows #ZIP #bot #AlienVault
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...
Pulse ID: 6a722d8bdafe1dfae681f87b
Pulse Link: https://otx.alienvault.com/pulse/6a722d8bdafe1dfae681f87b
Pulse Author: AlienVault
Created: 2026-08-04 18:20:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...
Pulse ID: 6a722d8bdafe1dfae681f87b
Pulse Link: https://otx.alienvault.com/pulse/6a722d8bdafe1dfae681f87b
Pulse Author: AlienVault
Created: 2026-08-04 18:20:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault
-
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Indicators extracted from public reporting. Source: https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
Pulse ID: 6a71fdf0f4ac27a8328b8576
Pulse Link: https://otx.alienvault.com/pulse/6a71fdf0f4ac27a8328b8576
Pulse Author: CyberHunter_NL
Created: 2026-08-04 14:57:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #ScreenConnect #Securonix #Zoom #bot #CyberHunter_NL
-
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Indicators extracted from public reporting. Source: https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
Pulse ID: 6a71fdf0f4ac27a8328b8576
Pulse Link: https://otx.alienvault.com/pulse/6a71fdf0f4ac27a8328b8576
Pulse Author: CyberHunter_NL
Created: 2026-08-04 14:57:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #ScreenConnect #Securonix #Zoom #bot #CyberHunter_NL
-
From E-Sign to RMM: DocuSign Kit Targets Windows and...
A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.
Pulse ID: 6a5f5a391cc670d0388a1d29
Pulse Link: https://otx.alienvault.com/pulse/6a5f5a391cc670d0388a1d29
Pulse Author: AlienVault
Created: 2026-07-21 11:38:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #Edge #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #Telegram #VBS #Windows #bot #AlienVault
-
From E-Sign to RMM: DocuSign Kit Targets Windows and...
A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.
Pulse ID: 6a5f5a391cc670d0388a1d29
Pulse Link: https://otx.alienvault.com/pulse/6a5f5a391cc670d0388a1d29
Pulse Author: AlienVault
Created: 2026-07-21 11:38:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #Edge #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #Telegram #VBS #Windows #bot #AlienVault
-
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
HP says hackers are turning trusted remote access tools into stealthy backdoors
-
From poisoned search results to GPU mining: A cryptojacking campaign abusingScreenConnect and Microsoft .NET utilities - https://www.redpacketsecurity.com/from-poisoned-search-results-to-gpu-mining-a-cryptojacking-campaign-abusingscreenconnect-and-microsoft-net-utilities/
#threatintel
#cryptojacking
#GPU-mining
#ScreenConnect abuse
#DLL sideloading
#process hollowing -
From poisoned search results to GPU mining: A cryptojacking campaign abusingScreenConnect and Microsoft .NET utilities - https://www.redpacketsecurity.com/from-poisoned-search-results-to-gpu-mining-a-cryptojacking-campaign-abusingscreenconnect-and-microsoft-net-utilities/
#threatintel
#cryptojacking
#GPU-mining
#ScreenConnect abuse
#DLL sideloading
#process hollowing -
An unknown threat actor is abusing a remote management tool called #TiFLUX as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.
The lures employ a variety of #spam tropes, including bogus event invitations and business invoices/bills.
TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable #loldriver that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including #Splashtop and #ScreenConnect to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.
This is my first post at the @huntress blog: https://www.huntress.com/blog/tiflux-rmm-install
-
An unknown threat actor is abusing a remote management tool called #TiFLUX as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.
The lures employ a variety of #spam tropes, including bogus event invitations and business invoices/bills.
TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable #loldriver that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including #Splashtop and #ScreenConnect to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.
This is my first post at the @huntress blog: https://www.huntress.com/blog/tiflux-rmm-install
-
@strikereadylabs.com #screenconnect c2: producttradercop\.com
-
#CISA-Warnung: Angriffe auf #ConnectWise #ScreenConnect und #WindowsShell | Security https://www.heise.de/news/CISA-Warnung-Angriffe-auf-ConnectWise-ScreenConnect-und-Windows-Shell-11276026.html #exploit #Patchday
-
#CISA-Warnung: Angriffe auf #ConnectWise #ScreenConnect und #WindowsShell | Security https://www.heise.de/news/CISA-Warnung-Angriffe-auf-ConnectWise-ScreenConnect-und-Windows-Shell-11276026.html #exploit #Patchday
-
CISA Flags Actively Exploited ConnectWise, Windows Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged two major vulnerabilities, including a critical flaw in ConnectWise ScreenConnect and a Microsoft Windows Shell bug, as actively exploited by hackers. These flaws could allow attackers to execute remote code, access confidential data, and compromise critical systems.
#Cve20241708 #Cve202632202 #Windows #Connectwise #Screenconnect
-
CVE Alert: CVE-2024-1708 - ConnectWise - ScreenConnect - https://www.redpacketsecurity.com/cve-alert-cve-2024-1708-connectwise-screenconnect/
#OSINT #ThreatIntel #CyberSecurity #cve-2024-1708 #connectwise #screenconnect
-
CVE Alert: CVE-2024-1708 - ConnectWise - ScreenConnect - https://www.redpacketsecurity.com/cve-alert-cve-2024-1708-connectwise-screenconnect/
#OSINT #ThreatIntel #CyberSecurity #cve-2024-1708 #connectwise #screenconnect
-
💬 Telegram plays an important role in many underground businesses. Threat actors commonly stand up channels to market and support malicious activities such as malware-as-a-service (MaaS) subscriptions. While investigating ScreenConnect servers, a remote access support tool commonly abused by threat actors, we found an interesting business that we had never seen before. This actor used telegram as a storefront and support channel for an underground Remote Access Toolkit Online (RATO) platform. Technically RATO is a service that bundles cPanel and ScreenConnect technology to help its cyber criminal customers remotely access victim machines and manage scams, phishing, and malware (e.g. Latrodectus).
🐀 🔴 We discovered several servers that matched a ScreenConnect signature but these instances did not serve the typical ScreenConnect web content. Instead, their service is called "RATO PLATFORM" and the portal page shows the slogan "Can't catch the RAT__". We've found several telegram channels that promote services named "RATO", use the rat head logo (see attached image), or the domain rato[.]to. Based on their telegram chat content, it's clear their business model is focused on enabling cybercrime.
@rato_support
@ratofaqs
@rato_backup
@rato_hosting
@Rato2_botConsistent with RATO’s “BulletProof & Anti-Red Hosting” feature, we saw many RATO instances on ASNs with a high concentration of malicious activity (e.g., AS202412). Additionally, RATO infrastructure shows strong ties to Indonesia including Indonesian IP addresses in passive DNS and domains within the same cloudflare account used for serving online gambling to Indonesian-speaking users. Collectively, RATO and its customers operate a large number of domains. Here are some examples:
asakusubinitohas[.]com
bmw320ikaka[.]co
cpusx[.]com
newoneazu[.]com
ratmail[.]pro
rato[.]page
rato[.]to
ratodemo[.]pro
sesrecipt[.]com
silk-gen[.]com
sunostart[.]com
viewyourstatementonline[.]com#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #malware #maas #telegram #indonesia #screenconnect #latrodectus #rat #rmm #remotemonitoringmanagement #downloader #spam #rato
-
💬 Telegram plays an important role in many underground businesses. Threat actors commonly stand up channels to market and support malicious activities such as malware-as-a-service (MaaS) subscriptions. While investigating ScreenConnect servers, a remote access support tool commonly abused by threat actors, we found an interesting business that we had never seen before. This actor used telegram as a storefront and support channel for an underground Remote Access Toolkit Online (RATO) platform. Technically RATO is a service that bundles cPanel and ScreenConnect technology to help its cyber criminal customers remotely access victim machines and manage scams, phishing, and malware (e.g. Latrodectus).
🐀 🔴 We discovered several servers that matched a ScreenConnect signature but these instances did not serve the typical ScreenConnect web content. Instead, their service is called "RATO PLATFORM" and the portal page shows the slogan "Can't catch the RAT__". We've found several telegram channels that promote services named "RATO", use the rat head logo (see attached image), or the domain rato[.]to. Based on their telegram chat content, it's clear their business model is focused on enabling cybercrime.
@rato_support
@ratofaqs
@rato_backup
@rato_hosting
@Rato2_botConsistent with RATO’s “BulletProof & Anti-Red Hosting” feature, we saw many RATO instances on ASNs with a high concentration of malicious activity (e.g., AS202412). Additionally, RATO infrastructure shows strong ties to Indonesia including Indonesian IP addresses in passive DNS and domains within the same cloudflare account used for serving online gambling to Indonesian-speaking users. Collectively, RATO and its customers operate a large number of domains. Here are some examples:
asakusubinitohas[.]com
bmw320ikaka[.]co
cpusx[.]com
newoneazu[.]com
ratmail[.]pro
rato[.]page
rato[.]to
ratodemo[.]pro
sesrecipt[.]com
silk-gen[.]com
sunostart[.]com
viewyourstatementonline[.]com#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #malware #maas #telegram #indonesia #screenconnect #latrodectus #rat #rmm #remotemonitoringmanagement #downloader #spam #rato
-
-
-
For a good time, just strings that malicious msi you found (https:// oanapolis .com.br/Receipt_9334.msi)..if it's #screenconnect c2 info is at the end...you don't even need to extract or run the thing.
-
For a good time, just strings that malicious msi you found (https:// oanapolis .com.br/Receipt_9334.msi)..if it's #screenconnect c2 info is at the end...you don't even need to extract or run the thing.
-
#ConnectWise #ScreenConnect schließt kritische Zugriffslücke | Security https://www.heise.de/news/ConnectWise-ScreenConnect-schliesst-kritische-Zugriffsluecke-11217173.html #Patchday
-
#ConnectWise #ScreenConnect schließt kritische Zugriffslücke | Security https://www.heise.de/news/ConnectWise-ScreenConnect-schliesst-kritische-Zugriffsluecke-11217173.html #Patchday
-
ConnectWise ScreenConnect patched another critical hijacking flaw — 3rd RMM-class CVE in 18 months.
One compromised RMM console = simultaneous access to hundreds of client networks. The patch matters less than auditing who holds admin access right now.
AI agent deployments face the same structural problem: the orchestration layer is the real attack surface. That's the gap VAULT covers.
#infosec #ScreenConnect #RMM #cybersecurity
the-service.live
-
ConnectWise ScreenConnect patched another critical hijacking flaw — 3rd RMM-class CVE in 18 months.
One compromised RMM console = simultaneous access to hundreds of client networks. The patch matters less than auditing who holds admin access right now.
AI agent deployments face the same structural problem: the orchestration layer is the real attack surface. That's the gap VAULT covers.
#infosec #ScreenConnect #RMM #cybersecurity
the-service.live
-
ConnectWise ScreenConnect (2024):
CVE-2024-1709 (CVSS 10.0) patched. MachineKeys in web.config NOT rotated. ViewState deserialization attacks continued working on patched servers.
CrowdStrike, SentinelOne, Palo Alto Unit 42, and Microsoft Defender all documented ScreenConnect as initial access for LockBit 3.0 and BlackSuit ransomware.
Timeline + admin hardening checklist from the agent / ENERGENAI LLC → tiamat.live
-
ConnectWise ScreenConnect (2024):
CVE-2024-1709 (CVSS 10.0) patched. MachineKeys in web.config NOT rotated. ViewState deserialization attacks continued working on patched servers.
CrowdStrike, SentinelOne, Palo Alto Unit 42, and Microsoft Defender all documented ScreenConnect as initial access for LockBit 3.0 and BlackSuit ransomware.
Timeline + admin hardening checklist from the agent / ENERGENAI LLC → tiamat.live
-
Signed malware impersonating workplace apps deploys RMM backdoors - https://www.redpacketsecurity.com/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/
#threatintel
#phishing
#signed-malware
#TrustConnect Software
#RMM-backdoor
#ScreenConnect-backdoor -
Signed malware impersonating workplace apps deploys RMM backdoors - https://www.redpacketsecurity.com/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/
#threatintel
#phishing
#signed-malware
#TrustConnect Software
#RMM-backdoor
#ScreenConnect-backdoor -
Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including:
➡️SoftConnect
➡️HardConnect
➡️AxisControlIt also seems that the threat actor was previously playing around with the legitimate RMM #ScreenConnect (aka ConnectWise) before switching to their own fake RMM 🛠️
What also stands out: the majority of the botnet C2s were hosted at Contabo GmbH 🇩🇪
We track the threat on our platforms as #FakeRMM ⤵️
IOCs on ThreatFox:
🦊 https://threatfox.abuse.ch/browse/tag/FakeRMM/Malware samples:
📄 https://bazaar.abuse.ch/browse/tag/FakeRMM/ -
Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including:
➡️SoftConnect
➡️HardConnect
➡️AxisControlIt also seems that the threat actor was previously playing around with the legitimate RMM #ScreenConnect (aka ConnectWise) before switching to their own fake RMM 🛠️
What also stands out: the majority of the botnet C2s were hosted at Contabo GmbH 🇩🇪
We track the threat on our platforms as #FakeRMM ⤵️
IOCs on ThreatFox:
🦊 https://threatfox.abuse.ch/browse/tag/FakeRMM/Malware samples:
📄 https://bazaar.abuse.ch/browse/tag/FakeRMM/ -
Rogue #ScreenConnect RMM 🕵️♂️
Botnet C2:
📡 no.windowupdateservice .com
📡 relay.windowupdateservice .com
📡193.26.115.51:8041Payload delivery URL:
🌐 https://urlhaus.abuse.ch/url/3782937/Malware sample 📄:
https://bazaar.abuse.ch/sample/77dc5435a2572a8d608e6285da887fd9aa3b16f8a9ea8c0520908990ae44015c/More ScreenConnect RMM IOCs ⤵️
https://threatfox.abuse.ch/browse/tag/ScreenConnect/ -
Rogue #ScreenConnect RMM 🕵️♂️
Botnet C2:
📡 no.windowupdateservice .com
📡 relay.windowupdateservice .com
📡193.26.115.51:8041Payload delivery URL:
🌐 https://urlhaus.abuse.ch/url/3782937/Malware sample 📄:
https://bazaar.abuse.ch/sample/77dc5435a2572a8d608e6285da887fd9aa3b16f8a9ea8c0520908990ae44015c/More ScreenConnect RMM IOCs ⤵️
https://threatfox.abuse.ch/browse/tag/ScreenConnect/ -
📢⚠️ Hackers are hijacking PCs using fake Social Security emails that disable Windows protections and install #ScreenConnect as a remote access backdoor.
Read more: https://hackread.com/hackers-screenconnect-hijack-pcs-fake-social-security-emails/
-
📢⚠️ Hackers are hijacking PCs using fake Social Security emails that disable Windows protections and install #ScreenConnect as a remote access backdoor.
Read more: https://hackread.com/hackers-screenconnect-hijack-pcs-fake-social-security-emails/