Living Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains
ID: d1b4576a-6f0b-592b-84c4-aede9718d06b
STIX ID: report--d1b4576a-6f0b-592b-84c4-aede9718d06b
Feed Name: TrendAI Security Blog
TrendAI Vision One™ MDR observed multiple separate intrusions where threat actors weaponized legitimate, code-signed ScreenConnect (and in one case SimpleHelp) installations as covert RATs delivered via phishing, SEO-poisoned downloads, malvertising, and RMM-to-RMM chaining; successful installs yielded SYSTEM-level remote control, credential-provider persistence, relay-based C2 on port 8041, scripted eviction of competing RMMs, and multi-host rotating infrastructure. The report maps delivery and persistence techniques, provides IOCs and hunting queries, links the activity to similar public reporting, and recommends allowlisting, URL/path filtering, segmentation for RMM, and email-sensor integration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
