logo

Hackers turn ScreenConnect into malware using Authenticode stuffing

ID: f3bf9312-284f-5093-bcb7-40dd4c0b317d

STIX ID: report--f3bf9312-284f-5093-bcb7-40dd4c0b317d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-06-25

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Researchers observed threat actors modifying ConnectWise ScreenConnect installer certificates (a technique called "authenticode stuffing") to embed malicious configuration while keeping binaries signed, then distributing these trojanized clients via phishing (PDFs and intermediary Canva pages linking to executables hosted on Cloudflare R2). The malicious ScreenConnect clients connect to attacker-controlled infrastructure (example IP 86.38.225.6:8041) and display deceptive UI (fake Windows Update) to stealthily gain remote access; G DATA extracted settings, flagged samples as Win32.Backdoor.EvilConwi.*, and ConnectWise revoked the abused certificate. The report also notes similar trojanized enterprise software (SonicWall NetExtender) used to steal credentials, underscoring supply/client distribution risks and the need to obtain software from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.