Hackers turn ScreenConnect into malware using Authenticode stuffing
ID: f3bf9312-284f-5093-bcb7-40dd4c0b317d
STIX ID: report--f3bf9312-284f-5093-bcb7-40dd4c0b317d
Feed Name: Bleeping Computer
Researchers observed threat actors modifying ConnectWise ScreenConnect installer certificates (a technique called "authenticode stuffing") to embed malicious configuration while keeping binaries signed, then distributing these trojanized clients via phishing (PDFs and intermediary Canva pages linking to executables hosted on Cloudflare R2). The malicious ScreenConnect clients connect to attacker-controlled infrastructure (example IP 86.38.225.6:8041) and display deceptive UI (fake Windows Update) to stealthily gain remote access; G DATA extracted settings, flagged samples as Win32.Backdoor.EvilConwi.*, and ConnectWise revoked the abused certificate. The report also notes similar trojanized enterprise software (SonicWall NetExtender) used to steal credentials, underscoring supply/client distribution risks and the need to obtain software from official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
