logo

Guide: How to Know if your ScreenConnect Server is Hacked | Huntress

ID: 655588ba-a990-50aa-9fc2-70aa34bd714b

STIX ID: report--655588ba-a990-50aa-9fc2-70aa34bd714b

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2024-02-24

Date Updated: 2026-04-28

...
...

Huntress reports active exploitation of two ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708, CVE-2024-1709), dubbed "SlashAndGrab," used to deliver malware; on-prem ScreenConnect servers and workstation instances are at risk. The advisory urges immediate patching to 23.9.8, describes IOCs (wiped/modified user.xml, zeroed timestamps, malicious .ashx extensions, activity around SetupWizard.aspx with Event ID 4663), and recommends isolating compromised hosts, disabling ScreenConnect services, resetting credentials, and deploying monitoring/mitigation tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.