Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
ID: 4ace2ce1-fcb9-5a4c-932f-1cbab3dca15a
STIX ID: report--4ace2ce1-fcb9-5a4c-932f-1cbab3dca15a
Feed Name: LevelBlue SpiderLabs Blog
**Executive summary:** LevelBlue OpsCTI documents a large-scale phishing campaign that impersonates software updates and trusted services (Google Meet, Microsoft Store, Apple App Store, DocuSign, Adobe, etc.) to trick victims into silently downloading preconfigured ConnectWise ScreenConnect clients; these installers auto-register to attacker-controlled ScreenConnect relays, enabling remote access. The report details infection flows, hosting and delivery mechanisms (attacker sites, AWS S3, Cloudflare R2), reusable artifacts and resource hashes for threat hunting, victim profiling techniques (including AI-assisted scripting and Telegram notifications), and provides extensive IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
