logo

Living Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains

ID: d1b4576a-6f0b-592b-84c4-aede9718d06b

STIX ID: report--d1b4576a-6f0b-592b-84c4-aede9718d06b

Feed Name: TrendAI Security Blog

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-08-18

...
...

TrendAI Vision One™ MDR observed multiple separate intrusions where threat actors weaponized legitimate, code-signed ScreenConnect (and in one case SimpleHelp) installations as covert RATs delivered via phishing, SEO-poisoned downloads, malvertising, and RMM-to-RMM chaining; successful installs yielded SYSTEM-level remote control, credential-provider persistence, relay-based C2 on port 8041, scripted eviction of competing RMMs, and multi-host rotating infrastructure. The report maps delivery and persistence techniques, provides IOCs and hunting queries, links the activity to similar public reporting, and recommends allowlisting, URL/path filtering, segmentation for RMM, and email-sensor integration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.