Thursday, August 20, 2026

Hackers Persist in Using ConnectWise ScreenConnect Tool to Distribute Malware

Hackers continue to exploit the ConnectWise ScreenConnect remote management and monitoring (RMM) tool to deploy malicious payloads, with a focus on financial organizations.

An independent researcher first reported a potential critical vulnerability in ScreenConnect versions 23.9.7 and prior through the ConnectWise Trust Center’s vulnerability disclosure program.

Malicious Campaigns Targeting Financial Organizations

This flaw has since been leveraged by threat actors, notably in May 2025, as observed by CyberProof Analysts and Threat Hunters.

They identified a wave of attacks utilizing signed malicious droppers, likely tied to the CHAINVERB backdoor associated with the UNC5952 threat group.

These attacks predominantly use phishing emails with invoice themes to trick users into downloading harmful executables.

ScreenConnect
Malicious url in the email leading to download of Document.exe 

The exploitation of top-level domains (TLDs) such as .top and anondns.net in command-and-control (C2) infrastructure further amplifies the reach of these eCrime campaigns, signaling a persistent and evolving threat landscape.

Technical Breakdown of the CHAINVERB Backdoor

Delving deeper into the technical intricacies, the CHAINVERB downloader represents a sophisticated tool in the arsenal of cybercriminals.

It exploits digital signatures within Windows executables to embed hidden C2 URLs within certificates, enabling the download and execution of subsequent payloads.

Once installed, often through deceptive filenames mimicking legitimate software like Adobe Reader or Zoom Installer, CHAINVERB deploys the ConnectWise ScreenConnect tool to establish remote desktop sessions with attacker-controlled servers.

This access facilitates internal host reconnaissance and screenshot capture, posing significant risks of data theft and further network compromise.

Specific instances include phishing emails from senders like “[email protected]” delivering malicious PDFs with URLs leading to downloads of executables like “Download.exe,” signed fraudulently under “ConnectWise, LLC.”

ScreenConnect
File is digitally signed by Connectwise, LLC 

Telemetry data also revealed C2 communications to domains such as kasin22.anondns.net and yertoje.uzhelp.top, alongside malicious webpages impersonating customer support portals to distribute droppers named Support.Client (1).exe.

ConnectWise acknowledged a potential breach by a nation-state threat group on May 28, 2025, currently under investigation by Mandiant, though direct links to these specific observations remain under review.

According to the Report, Organizations are urged to adopt robust threat hunting practices and upgrade to patched versions (23.9.8 or later) following specified upgrade paths to mitigate risks, alongside implementing CISA-recommended defenses against phishing and unauthorized RMM software use.

This table provides a snapshot of key IOCs associated with the campaign, aiding defenders in identifying and blocking malicious activities tied to these attacks.

Continued vigilance and updates from ongoing investigations will be critical to curbing this threat.

Indicators of Compromise (IOCs)

TypeIndicator
Domainpolarof.koyhelp.top
Domainwww.v4shelp.top
Domainhelpw8.top
Domainyertoje.uzhelp.top
Domainweb.bcqhelp.top
Domainweb.mryhelp.top
Hash (MD5)a01a80d8c1f665eda5a81391a1ed0024
Hash (MD5)180f9294e3e2418a460dee6d9e40291a
Email Sender[email protected]
C2 Domainkasin22.anondns.net

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays

ToxicPanda 2.0, an evolved Android banking Trojan that significantly...

Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files

Cisco has issued security updates for a high-severity vulnerability...

Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security

Threat actors are pairing fake CAPTCHA verification pages with...

Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services

Red Hat has disclosed CVE-2026-66794, an important-severity server-side request...

Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE

Splunk has released a security hardening update addressing 17...

Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud

Threat actors are increasingly abusing Microsoft 365 identity sessions...

CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access

Researchers have revealed a pre-authentication remote code execution (RCE)...

Related Articles

Recent News