logo

SlashAndGrab: ScreenConnect Post-Exploitation in the Wild (CVE-2024-1709 & CVE-2024-1708)

ID: 10408c40-79c0-5f9f-8e99-db776edf522a

STIX ID: report--10408c40-79c0-5f9f-8e99-db776edf522a

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-26

Date Updated: 2026-04-28

...
...

Huntress SOC observed active, widespread exploitation of a ScreenConnect authentication-bypass/path-traversal vulnerability ("SlashAndGrab") that allowed attackers to create privileged accounts and perform post-compromise activities including deploying LockBit and other ransomware, dropping Cobalt Strike beacons, installing cryptocurrency miners, and installing alternate remote-access/RMM tools for persistence; the report includes ATT&CK mappings, detailed TTP descriptions, and a comprehensive set of IoCs (file paths, hashes, URLs, and IPs) to support detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.