Attackers Distributed Malicious ScreenConnect Clients
Threat actors are masking remote access tools with legitimate digital signatures to bypass standard security filters.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?
Attackers have launched a phishing campaign that distributes malicious ScreenConnect client installers disguised as wire transfer receipts. This activity, reported on October 1, 2026, uses legitimate software signatures to evade detection.
Why it matters
The campaign highlights the ongoing security challenge of 'living-off-the-land' techniques, where attackers repurpose legitimate remote monitoring tools to maintain unauthorized network access. By using trusted, signed binaries, these actors successfully bypass many standard endpoint security controls.
The malicious executable, ScreenConnect.ClientSetup.exe, carries a legitimate digital signature from ConnectWise, LLC. Initial analysis showed the file bypassed detection on VirusTotal, relying on browser-based warnings as the primary line of defense.
The players
ConnectWise, LLC
A developer of remote monitoring and management software, including the ScreenConnect platform, whose legitimate digital signature was leveraged in this campaign.
The details
The attackers distribute a legitimate, preconfigured remote monitoring and management (RMM) client that connects to an attacker-controlled account upon execution. Because the installer is a signed, authentic application, it circumvents basic reputation-based security filters. Once the client is installed, the attackers gain remote administrative access to the host machine through established management infrastructure.
Timeline
October 1, 2026: The phishing campaign was identified and reported.
The Tech Race
This activity follows a long-standing pattern of threat actors abusing legitimate administrative utilities, a trend documented by the LOLRMM project remote management tool list. It illustrates the ongoing race between security vendors attempting to flag malicious RMM usage and attackers exploiting the trust embedded in signed enterprise software.
Users should treat unexpected wire transfer receipts, especially those featuring amounts like $5,745.65, with extreme skepticism. Regardless of whether a download file appears digitally signed by a known vendor, users must rely on browser and endpoint security alerts to block unauthorized execution.
The takeaway
Security teams must transition from reputation-based blocking to behavioral analysis to detect when legitimate administrative tools are being used by unauthorized actors. Organizations should monitor their environments for unauthorized RMM installations, even if the files carry valid corporate signatures.
Further reading
For more on how legitimate administrative tools are being co-opted, review the latest trends in Cybersecurity.
More information
Review the full catalog of abused administrative tools on the LOLRMM project remote management tool list.
Source note: This article includes information reported by SANS Internet Storm Center.
Live Poll
Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?







