ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ID: aaff0881-a3cd-5ea4-8070-01cd17712146
STIX ID: report--aaff0881-a3cd-5ea4-8070-01cd17712146
Feed Name: GBHackers
SMOKE#SCREEN is a multi-wave, cross-platform campaign that silently deploys signed ConnectWise ScreenConnect agents via phishing lures (Zoom, Adobe, business documents) and obfuscated droppers/loaders; attackers hide execution windows, erase forensic artifacts, and use attacker-controlled relay servers to provide guest-like remote access, while evolving tradecraft to evade EDR/AV and leveraging reputable services (Dropbox, Cloudflare) for payload delivery. Securonix mapped multiple relay clusters and staging hosts, observed Defender tampering and Defender-evading loaders, and recommends inventorying ScreenConnect instances, flagging unknown relays/IP connections, and monitoring for AMSI/Defender tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
